Don’t do SECURITY. Do business SECURELY.

Ransomware attack on Synnovis disrupts London hospitals

A ransomware attack on pathology provider Synnovis forces south-east London NHS trusts to postpone thousands of appointments and operations.

A ransomware attack on Synnovis, which provides pathology services to NHS organisations in south-east London, severely disrupted blood tests and transfusions at King’s College Hospital and Guy’s and St Thomas’ NHS foundation trusts and at GP services across the area.

What happened

  • Ciaran Martin, the former chief executive of the National Cyber Security Centre, said he believed the attack was carried out by a Russian group of cyber criminals calling themselves Qilin.
  • NHS England reported that by 22 September 2024, 16 weeks after the attack, 10,152 acute outpatient appointments and 1,710 elective procedures had been postponed at the two trusts.
  • NHS Blood and Transplant appealed for O-positive and O-negative blood donors because hospitals could not match patients’ blood at normal rates.
  • Qilin published stolen data online on 20 June 2024, and in November 2025 Synnovis began notifying affected organisations that data including names, NHS numbers, and in some cases test results had been taken.

Why it mattered

It was one of the most disruptive cyber attacks on the NHS since WannaCry and showed how an attack on a single supplier can directly affect patient care across a whole region.

Lessons for organisations

Include critical suppliers in incident planning and exercise what happens if they go offline. Contracts should set clear security and reporting expectations, and certifications such as Cyber Essentials or ISO/IEC 27001 can help evidence a supplier’s baseline.

Sources: NHS England, BleepingComputer

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights