CSIDB logo
Incident

Mid and South Essex NHS Foundation Trust

Incident posture

Attack window
Jun 2024
Location
United Kingdom
Status
Historical
CIA posture
Available to members
Updated
2026-09-07 13:49

Linked entities

Victim
Mid and South Essex NHS Foundation Trust
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyber attack targeting third-party testing provider Synnovis resulted in the theft of 2,380 patient records belonging to Mid and South Essex NHS Foundation Trust, which operates Broomfield, Basildon, and Southend hospitals. The breach affected data from blood, urine, and tissue sample analyses, with stolen information potentially including names, dates of birth, patient numbers, NHS numbers, postcodes, and test results. The Russia-based criminal group Qilin claimed responsibility for the attack, and the stolen data was later published on the dark web, though Synnovis stated there was no evidence of malicious use and that the data was taken "in haste and in a random manner." Multiple NHS trusts were impacted by the same incident, with the affected organization confirming it was notified months after the breach and engaging cybersecurity experts to strengthen its own systems while preparing to contact those whose data was compromised.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

In June 2024, a Russia-based cyber-criminal group identified as Qilin carried out a ransomware attack against Synnovis, a third-party provider of pathology and diagnostic testing services. Synnovis analysed blood, urine, and tissue samples on behalf of a number of NHS organisations, including hospitals in London that depended heavily on the provider for testing and IT systems. The attackers were able to compromise Synnovis systems and exfiltrate data, which was later published on the dark web. Synnovis subsequently acknowledged that the data had been taken "in haste and in a random manner" and stated there was no evidence the stolen information had been used maliciously. The CEO of Synnovis, Mark Dollar, confirmed the company was offering its "full support" to the affected organisations.

Following the attack, Synnovis undertook a lengthy review of the stolen data to determine which NHS trusts and patients had been impacted. The company said it had notified all affected NHS trusts and indicated that individual trusts were responsible for informing their patients if their data had been taken. The stolen information potentially included patient names, dates of birth, patient numbers, NHS numbers, postcodes, and test results. Among the trusts impacted was Mid and South Essex NHS Foundation Trust (MSE), which operates Broomfield Hospital in Chelmsford, as well as Basildon and Southend hospitals. Although the breached data resided on Synnovis systems and did not relate to systems run directly by MSE, the trust confirmed that 2,380 patient records were involved. MSE was formally notified about the breach in December 2024, roughly six months after the original attack in June 2024.

In the days following MSE's confirmation, other affected NHS organisations also came forward. Bedfordshire Hospitals NHS Foundation Trust disclosed that almost 33,000 of its patients had their data stolen in the same Synnovis breach. The exact total number of NHS trusts affected has not been publicly disclosed. Within MSE, the records identified as compromised related to a mixture of specialist diagnostic tests. Because some of the data was not directly linked to individual patients, the trust indicated it was still waiting for confirmation on exact numbers. Dawn Scrafield, deputy chief executive of MSE, stated that once the trust had established which patients were affected, it would be contacting them directly.

In response to the incident, MSE confirmed at a recent board meeting that it had brought in cyber security experts to strengthen its own internal systems, even though the breach itself originated with the third-party provider rather than the trust's own infrastructure. The trust committed to contacting those patients whose data had been confirmed as taken once the reconciliation process between the stolen data and MSE's patient records had been completed. Synnovis continued to coordinate with affected NHS trusts and provided assurances regarding its ongoing support and investigation. Approximately two years elapsed between the original June 2024 attack and the June 2026 public disclosure by MSE regarding the 2,380 records identified within its patient population. The incident highlighted the supply-chain risk posed by third-party pathology providers and the extended period required to fully reconcile and notify impacted patients following a major healthcare data breach.

Sources

Sources available to members: 1 source.

CSIDB