Don’t do SECURITY. Do business SECURELY.

Ransomware attack on NHS software supplier Advanced disrupts NHS 111

A LockBit ransomware attack on software provider Advanced took down systems used by NHS 111 and care providers across the UK.

A ransomware attack on software provider Advanced took down systems used by NHS 111, GP out-of-hours services, and social care providers, forcing many to fall back on paper. The LockBit ransomware gang was reported to be behind the attack.

What happened

  • Advanced’s Adastra patient management system, used by most NHS 111 services, was among those affected.
  • Some services took weeks to restore, and staff worked with paper records in the meantime.
  • Attackers were reported to have got in using a customer account that lacked multi-factor authentication.
  • In March 2025 the ICO fined Advanced’s health and care subsidiary just over £3m, its first fine against a data processor under UK GDPR.

Why it mattered

The incident showed how a single supplier compromise can disrupt frontline health services nationwide, and it set a precedent for regulators holding processors directly accountable. The NCSC and NHS England were involved in the response.

Lessons for organisations

Organisations should enforce multi-factor authentication on all remote access, including accounts used by customers and suppliers, and should assess critical suppliers’ security as part of their own risk management. Contracts with key suppliers should set out security requirements, incident notification, and recovery expectations.

Sources: ICO, BleepingComputer

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with a link to our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights