CSIDB logo
Incident

DXS International

Incident posture

Attack window
Dec 2025
Location
United Kingdom
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 15:08

Linked entities

Victim
DXS International
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Dec 2025
Disclosed
Dec 2025
Resolved
Pending

Summary

DXS International, a UK‑based supplier of NHS‑approved clinical support solutions, disclosed that it had suffered a cyber‑attack affecting its office servers. The company stated that the intrusion caused minimal impact on its services and that front‑line NHS clinical operations remained unaffected. A threat actor claimed to have exfiltrated approximately 300 GB of data and threatened to release it, although the claim has not been confirmed by DXS International or the NHS. The firm also indicated that it does not expect the incident to result in adverse financial consequences at this time.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On December 14, 2025, DXS International discovered a cyber-attack that affected its office servers. The company confirmed the incident in a filing to the London Stock Exchange on December 18, 2025. DXS International is a UK-based technology supplier that provides NHS-approved clinical support solutions for clinicians and patients and is an official partner of NHS England. The filing noted that the attack was identified on the date of discovery and that the compromised systems were limited to office infrastructure.

According to the filing, the cyber-attack caused minimal impact on the company’s services and front-line clinical services remained unaffected and operational. DXS International stated that it did not anticipate the incident would have an adverse financial impact at that time. The company emphasized that its NHS-related services continued to function without disruption despite the breach of its office servers.

On the same day the attack was discovered, a threat actor known as Devman listed DXS International on their data leak site, claiming to have exfiltrated 300 gigabytes of data from the company. Devman threatened to release the stolen data on December 20, 2025. Neither DXS International nor the NHS has confirmed the validity of the claim or the alleged data theft.

Sources

Sources available to members: 1 source.

CSIDB