Russian cyber gang thought to be behind ransomware attack that hit London hospitals

| | London
1 2 3 4 5
  • 0

Russian cyber gang thought to be behind ransomware attack that hit London hospitals

Thursday, 06 June 2024 | AP | London

A Russian cyber gang is believed to be behind a ransomware attack that disrupted London hospitals and led to operations and appointments being cancelled, the former head of British cybersecurity said Wednesday. A group known as Qilin is most likely behind the attack on Synnovis, which provides pathology lab services for several hospitals run by the National Health Service, said Ciaran Martin, former chief executive of the National Cyber Security Centre.

Martin said it was one of the more serious ransomware attacks in the UK because it disabled operations. “It’s the more serious type of ransomware where the system just doesn’t work,” Martin told BBC Radio 4. “If you’re working in healthcare in this trust, you’re just not getting those results so it’s actually seriously disruptive.” The incident Monday affected King’s College and Guy’s and St Thomas’ hospital trusts, which run several south London hospitals, as well as clinics and doctors’ practices across a swath of the city, the NHS said.

A memo to staff called it a “critical incident” and said it had a “major impact” on services, particularly blood transfusions. Procedures and operations were cancelled or redirected elsewhere. The incident was reported to police.

Synnovis Chief Executive Mark Dollar said Tuesday that it was still trying to understand what happened. The company offered no further comment Wednesday. Ransomware involves criminals paralysing computer systems with malware, then demanding money to release them.

Ransomware is the costliest and most disruptive form of cybercrime, affecting local governments, court systems, hospitals and schools as well as businesses. It is difficult to combat as most gangs are based in former Soviet states and out of reach of Western justice.

Britain’s state-funded health system has been hit before, including during a 2017 ransomware attack that froze computers at hospitals across the country, closing down wards, shutting emergency rooms and bringing treatment to a halt.

Qilin, also known as Agenda, advertises on dark web cybercrime forums and leases malware to affiliates who use it to conduct attacks for a percentage of ransom payments, said Louise Ferrett of Searchlight Cyber, a threat intelligence company. The group has listed more than 100 victims.  

Trending News

more

State Editions

NGT seeks details on compensation to kin of Narela fire victims

07 April 2025 | Pioneer News Service | Delhi

Foundation Day celebrations held

07 April 2025 | Pioneer News Service | Delhi

Sewer-cleaning machine trial held in GK area

07 April 2025 | Pioneer News Service | Delhi

Two held for threatening realty dealer with firearm

07 April 2025 | Pioneer News Service | Delhi

Assembly hold Mahavir Gatha

07 April 2025 | Pioneer News Service | Delhi

NGT seeks details on compensation to kin of Narela fire victims

07 April 2025 | Pioneer News Service | Delhi

Sunday Edition

A Traveller’s Diary Through Vibrant Vietnam

06 April 2025 | Rohit Kaul | Agenda

The unwanted becomes unforgettable

06 April 2025 | SAKSHI PRIYA | Agenda

Taste of Burmese celebrations in India

06 April 2025 | Abhi Singhal | Agenda

Cool, Creamy and Irresistible

06 April 2025 | Abhi Singhal | Agenda

Find Your Perfect Summer Cool-Down

06 April 2025 | SAKSHI PRIYA | Agenda

Hiking to the heights

06 April 2025 | Abhi Singhal | Agenda

A Traveller’s Diary Through Vibrant Vietnam

06 April 2025 | Rohit Kaul | Agenda

The unwanted becomes unforgettable

06 April 2025 | SAKSHI PRIYA | Agenda