Synnovis, a British pathology laboratory services firm, has begun notifying UK healthcare providers that patient data may have been compromised in a ransomware attack that occurred in June 2024. The attack disrupted laboratory services and caused blood shortages, significantly impacting patient care for several months. Following a complex forensic investigation, Synnovis determined that cybercriminals stole data in a hasty and disorganized manner from a working drive, resulting in fragmented and unstructured data exfiltration.
The company stated that none of the stolen data originated from its primary laboratory database. Under UK data protection law, Synnovis is responsible for informing healthcare providers, who must then notify affected patients if necessary. The notification process follows more than a year of investigation to identify the scope and nature of the compromised data. Synnovis emphasized the challenges in analyzing the stolen data due to its random and untargeted extraction during the cyberattack.

See the actors and campaigns active against you right now.
9 events from the most recent confirmed update back to the earliest known activity.
South London and Maudsley NHS Foundation Trust said the June 2024 Synnovis ransomware attack was still disrupting pathology services into January 2026. The trust remained in business continuity mode using manual processes, with 161,560 pathology reports still not entered into patient records and pathology reports unavailable in the London Care Record.
Reporting on November 13, 2025 said Synnovis expected its notification process to affected healthcare providers to finish by November 21. The notices concerned exfiltrated data including names, dates of birth, NHS numbers, and in some cases medical test information.
By mid-November 2025, Synnovis said it had completed its forensic investigation into the June 2024 Qilin attack. The company said it still had not determined the attackers' initial access vector, although compromised infrastructure had been replaced.
By November 2025, reporting on the Synnovis incident noted that the ransomware attack had been linked to a patient fatality. This marked the incident as one of the most serious and disruptive cyberattacks affecting recent NHS operations.
In November 2025, Synnovis started informing NHS providers and partner organizations about which patients' data had been stolen in the 2024 breach. Under UK data protection rules, the affected healthcare organizations, rather than Synnovis, are responsible for notifying individual patients.
Over the following year, Synnovis conducted a lengthy forensic investigation into the breach. The review was prolonged because the stolen data was unstructured and fragmented, requiring specialized analysis to determine what had been taken and who was affected.
After ransom payment was refused, the Qilin gang dumped exfiltrated Synnovis data online. The leaked information included patient-related data such as personal identifiers and, in some cases, test results.
Following the June 2024 attack, Synnovis and its NHS partners decided not to pay the attackers' ransom demand. The decision was later followed by the threat actors publishing stolen data online as part of a double-extortion tactic.
In June 2024, pathology provider Synnovis was hit by a ransomware attack attributed to the Qilin gang. The incident severely disrupted pathology services for NHS hospitals in London, causing cancellations and postponements of operations and appointments and contributing to blood shortages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
7 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcego.theregister.com
Open sourcescworld.com
Open sourcetherecord.media
Open sourcebleepingcomputer.com
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.