Categories: Data Security InfoSec News

UK: NHS IT supplier held to ransom by hackers

Published by
RiSec.Mitch

A cyber-attack on a major IT provider of the NHS has been confirmed as a ransomware attack.

Advanced, which provides digital services like patient check-in and NHS 111, says it may take three to four weeks to fully recover.

Ransomware hackers take control of IT systems, steal data and demand a payment from victims to recover.

The NHS insists that disruption is minimal, but Advanced would not say whether NHS data had been stolen.

The Birmingham-based firm says it first spotted the hack at 07:00 BST on 4 August and immediately took steps to contain the hackers. It is now working to restore services.

The company refused to say if it was in negotiations with hackers or paying a ransom to them.

In a statement, it said: “We are rebuilding and restoring impacted systems in a separate and secure environment.”

An NHS England spokesperson said: “While Advanced has confirmed that the incident impacting their software is ransomware, the NHS has tried and tested contingency plans in place including robust defences to protect our own networks, as we work with the National Cyber Security Centre to fully understand the impact.

“The public should continue to use NHS services as normal, including NHS 111 for those who are unwell, although some people will face longer waits than usual.

“As ever, if it is an emergency, please call 999.”

An NHS psychiatrist, who wished to remain anonymous, told the BBC the attack left his team “making clinical decisions nearly blind”.

“If a new patient came to us, we weren’t able to read their history or know very much about them,” he said.

“The [local] trust are doing their best at setting up an alternative system, they’ve got a way that we can look at some historical notes now, and have set up another system to mean that we can input new notes.

“But there’s still basically a week’s worth of notes that we can’t access. We’ve been told to be ready for it to not be up and running for who knows how long.”

At the end of last week, family doctors in London were warned by NHS England they could see an increased number of patients sent to them by NHS 111 because of the “significant technical issue”, industry magazine Pulse reported.

Advanced initially said that only a “small number of servers” had been affected and that it might be able to recover in a week.

Products which have been affected include Adastra, which is used by NHS 111 service, and Caresys and Carenotes, which provide the backbone for care home services like patient notes and visitor booking.

The National Cyber Security Centre, which is part of GCHQ, says it is working with Advanced to help it recover.

A spokesman said: “Ransomware is the key cyber-threat facing the UK, and all organisations should take immediate steps to limit risk by following our advice on how to put in place robust defences to protect their networks.”

Ransomware hackers are usually financially motivated and part of large, professionally run criminal gangs that target companies and demand hundreds of thousands, sometimes millions, of pounds in ransom in the form of cryptocurrencies like Bitcoin.

While it is hard to trace where the gangs are based, analysis suggests that 74% of all money made through ransomware attacks in 2021 went to Russia-linked hackers.

Suggest an edit to this article

Go to Cybersecurity Knowledge Base

Got to the Latest Cybersecurity News

Go to Cybersecurity Academy

Go to Homepage

Stay informed of the latest Cybersecurity trends, threats and developments. Sign up for our Weekly Cybersecurity Newsletter Today.

Remember, CyberSecurity Starts With You!

  • Globally, 30,000 websites are hacked daily.
  • 64% of companies worldwide have experienced at least one form of a cyber attack.
  • There were 20M breached records in March 2021.
  • In 2020, ransomware cases grew by 150%.
  • Email is responsible for around 94% of all malware.
  • Every 39 seconds, there is a new attack somewhere on the web.
  • An average of around 24,000 malicious mobile apps are blocked daily on the internet.
Bookmark
Please login to bookmark Close
Social Comments Box
Share the word, let's increase Cybersecurity Awareness as we know it

This post was last modified on 12 August 2022 1:32 PM

RiSec.Mitch

Just your average information security researcher from Delaware US.

Leave a Comment
Published by
RiSec.Mitch
Tags: NHS ransom UK

Recent Posts

  • Data Breach News
  • InfoSec News

WH Smith Announces Cyber-Attack: Employee Data Stolen

British high street chain WH Smith has recently revealed that it was hit by a…

2 years ago
  • InfoSec News
  • World Affairs

Voice ID: How Secure is it Really?

As banks worldwide roll out Voice ID as a means of user authentication over the…

2 years ago
  • Cybersecurity Academy
  • InfoSec News

What distinguishes Application Security from API Security?

In the era of digital transformation, cybersecurity has become a major concern for businesses. When…

2 years ago
  • Cybersecurity Academy
  • InfoSec News

The Top 5 Cybersecurity threats facing Businesses Today

In today's digital age, cybersecurity threats have become a significant concern for businesses of all…

2 years ago
  • InfoSec News
  • World Affairs

Enterprise users infected by RIG Exploit Kit thanks to Internet Explorer

The RIG Exploit Kit is currently in the midst of its most productive phase, attempting…

2 years ago
  • Cybersecurity Academy

The Rise and Rise of AI

One of the most transformational technologies of our time, artificial intelligence (AI), has quickly come…

2 years ago