Healthcare · United Kingdom · June 2024
Synnovis (NHS pathology) Ransomware Attack
In June 2024, a ransomware attack on Synnovis — a pathology provider for NHS trusts in south-east London — halted blood testing and transfusions across major hospitals, forcing cancelled operations and becoming one of the UK's most serious healthcare cyber incidents.
What happened
On June 3, 2024, Synnovis — a pathology partnership that provides laboratory services for several major NHS trusts in south-east London — was hit by a ransomware attack that quickly became one of the most serious healthcare cyber incidents the United Kingdom has experienced. Pathology may sound like a back-office function, but it is the invisible backbone of hospital care: blood tests, transfusion matching, and diagnostic results flow through it constantly. When Synnovis went dark, so did a large part of the clinical decision-making at the hospitals it served.
The attack was attributed in reporting to the Qilin ransomware operation, a Russia-linked group. Later analysis reportedly indicated that the intrusion was enabled in part by the absence of two-factor authentication — the same class of basic-control gap that has featured in other major healthcare attacks. Once inside, the attackers encrypted systems and exfiltrated sensitive data, which was subsequently published when no ransom was paid.
The affected trusts — including major London hospitals — were forced to declare critical incidents. Because pathology results underpin so many clinical pathways, the disruption cascaded far beyond the laboratory itself, touching surgery, oncology, maternity, and emergency care.
The impact
The operational impact was severe and sustained. Hospitals lost fast access to the blood tests and transfusion matching that many procedures depend on. Reporting later cited nearly 600 incidents linked to the attack, with around 170 of them directly affecting patient care — a rare, concrete accounting of how a cyberattack translates into clinical harm.
Thousands of appointments and operations were postponed across the affected trusts, and the NHS issued urgent appeals for O-type blood donations because hospitals could not reliably match patients' blood types without the normal laboratory systems. Clinicians fell back on manual processes and slower, more cautious protocols — safe, but far less efficient, and sustained over many weeks.
The data dimension added insult to injury: sensitive information was stolen and later published online, creating a privacy harm on top of the operational one. The recovery, and the clinical backlog it created, imposed substantial costs across the NHS trusts involved.
How the attack unfolded
- Initial access: attackers gained entry to Synnovis systems, reportedly aided by the absence of two-factor authentication.
- Escalation and access: the intruders reached the core laboratory systems that NHS trusts depended on.
- Exfiltration: sensitive data was copied out before encryption, later published when no ransom was paid.
- Encryption and impact: pathology systems were encrypted, halting blood testing and transfusion services and forcing hospitals to declare critical incidents.
The recovery
Recovery stretched across months rather than days. Synnovis and the NHS worked to restore laboratory systems and clear the enormous backlog of delayed tests and postponed procedures, all while operating under manual, degraded processes in the interim.
The prolonged timeline underscored how a single specialized supplier, deeply embedded in clinical workflows, can become a single point of failure for an entire regional health system — and how long it takes to safely rebuild when that happens.
How this attack could have been contained
The reported root-cause gap — access without two-factor authentication — is precisely what Immune's continuous access verification is designed to compensate for. By scoring behavior on every request rather than trusting a single authentication event, Immune raises an alarm when a credential begins acting abnormally, even where MFA is missing or bypassed.
The weeks between intrusion and full impact are the window resilience is built to exploit. Immune's network monitoring and deception layer target exactly that dwell time, surfacing lateral movement and staging before data is exfiltrated and systems encrypted.
For the core harm — months of halted pathology — Immune's containment confines an intrusion to a small segment, and its self-healing recovery restores validated, immutable backups in a controlled clinical order, designed to bring critical laboratory systems back in a defined window rather than over months of manual operation.
Sources
Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.
Related incidents
More ransomware attacks
In May 2017, the WannaCry ransomware worm swept through unpatched systems worldwide and hit the UK's NHS especially hard, reportedly cancelling around 19,000 appointments and becoming a landmark healthcare ransomware event.
The February 2024 ransomware attack on Change Healthcare disrupted medical claims and payments nationwide, affecting an estimated 100 million people and becoming one of the costliest healthcare cyberattacks on record.
Protect against attacks like this
How to defend against healthcare ransomware
Don't let an attack become a shutdown
See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.
