Synnovis Breach - UK Providers Notified of 2024 Data Theft
Category:Threat Alerts
Synnovis, a British pathology lab partnership between Guy's and St Thomas' NHS Foundation Trust, King's College Hospitals NHS Trust, and Synlab, completed forensic analysis of data stolen in June 2024 ransomware attack attributed to Qilin gang. The attack hit almost all IT systems, disrupting pathology services and leading to blood testing failures that canceled 10,152 acute outpatient appointments and 1,710 elective procedures at London hospitals. What made forensics difficult: attackers exfiltrated data "in haste from a working drive, in a random and untargeted manner"—resulting in fragmented, unstructured stolen data that took over a year to analyze. The stolen data came from working drives, not Synnovis' primary lab database. Some included NHS numbers, patient names, dates of birth, and a small amount of test results matched to individuals. Most test results appeared as numerical references or codes requiring clinical knowledge to interpret. Synnovis is now notifying affected healthcare providers by November 21, 2025. Under UK law, providers determine whether patient notification is necessary. The attack caused blood shortages lasting months—O-negative supplies dropped to unprecedented lows. NHS England later linked one patient death to delayed blood test results caused by the cyberattack. Synnovis did not pay ransom, stating this decision reflected "commitment to ethical principles and rejection of funding future cybercriminal activities." All IT services were restored by late fall 2024, with most applications rebuilt from scratch.
CORTEX Protocol Intelligence Assessment
Business Impact: The "smash-and-grab" exfiltration pattern is interesting—Qilin prioritized speed over precision, grabbing whatever was accessible rather than targeting specific datasets. This created a forensics nightmare but also suggests they were under time pressure or lacked deep knowledge of Synnovis' data architecture. The year-long analysis timeline reflects the complexity of mapping fragmented data back to healthcare providers using client codes, ODS codes, and manual file name analysis. The blood shortage cascade effect demonstrates how pathology lab compromise impacts entire regional healthcare systems beyond just the initial victim.
Strategic Intelligence Guidance
- Mandate third-party risk assessments and tabletop exercises for diagnostic vendors.
- Segment clinical systems and apply immutability to backups; test restore RTO/RPO.
- Define provider notification workflows and legal review for UK data laws.
- Instrument anomaly detection for exfiltration from working drives/shares.
Vendors
Threats
Targets
Intelligence Source: Synnovis Breach - UK Providers Notified of 2024 Data Theft | Nov 12, 2025