DXS International, a key technology supplier to the UK's National Health Service (NHS), experienced a cyberattack that targeted its internal office servers. The incident was detected and contained by DXS's IT staff in collaboration with NHS England, and a third-party digital forensics firm has been engaged to investigate the scope and nature of the breach. DXS reported the incident to the London Stock Exchange and notified relevant authorities, including the Information Commissioner's Office. The company stated that its clinical services and frontline operations remained unaffected, and there is currently no confirmation that NHS patient data was compromised.
DXS International provides widely used clinical decision support and referral management tools, supporting millions of NHS patients and a significant portion of GP referrals in England. While the company is not a core electronic health record provider, some of its systems process patient data to assist healthcare providers. The ongoing investigation aims to determine the full impact of the breach, and DXS has assured stakeholders that the incident is not expected to have a material adverse effect on its finances. The event highlights the growing risks faced by health technology suppliers and the potential implications for healthcare delivery, even when core patient records are not directly affected.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
DXS publicly disclosed the cyber incident in a stock exchange filing, said it was working with NHS cybersecurity teams and external forensic specialists, and notified authorities including the Information Commissioner's Office. The company said there was no confirmed impact on patient care and no confirmation that NHS patient data was compromised.
On December 15, 2025, a threat actor identified as Devman2 claimed responsibility for the DXS intrusion and alleged it stole 300 GB of data. The claim was reported without public proof.
DXS International said unauthorized access to its internal office servers occurred on December 14, 2025, affecting a technology supplier used across the NHS. The company said the incident was quickly contained and that frontline clinical services were not disrupted.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
3 references tracked. Mallory keeps watching after this page renders.
databreaches.net
Open sourcego.theregister.com
Open sourcetherecord.media
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.