A ransomware attack attributed to the Russia-based Qilin gang severely disrupted pathology and clinical services at London hospitals, with officials and media reports identifying the incident as the cause of widespread delays to treatment and diagnostics. Reporting on the fallout said nearly 200 cancer operations were postponed, alongside other surgeries and appointments, after systems supporting blood testing and related services were knocked offline. Qilin was identified in multiple reports as the group behind the intrusion, and it later published stolen NHS data online.
The consequences later escalated beyond operational disruption when a patient's death was confirmed to have been linked to the attack, underscoring the life-threatening impact of ransomware on healthcare delivery. Former NHS National Services Scotland CISO Alastair Mitchelson said such an outcome was tragic but not surprising when systems used for diagnosis and treatment fail at scale. Qilin reportedly expressed regret for the harm while denying responsibility, and claimed the attack was a political protest tied to grievances against the UK government.

See the actors and campaigns active against you right now.
5 events from the most recent confirmed update back to the earliest known activity.
A death was later confirmed following the cyberattack-related disruption to healthcare systems, making the incident one of the clearest examples of ransomware causing fatal real-world harm in medical services. Coverage also noted Qilin had expressed regret for the harm while denying responsibility for the death.
Reporting on the continuing impact said almost 200 cancer operations had been postponed at London hospitals because of the ransomware attack. The disruption highlighted the severe effect on patient care weeks after the initial breach.
Qilin published data stolen in the attack, escalating the incident from operational disruption to confirmed data exposure. The leak increased concerns about patient and healthcare information being compromised.
Within days of the disruption, reporting said Russian cyber criminals were thought to be behind the NHS attack, with the Russia-based ransomware group Qilin identified as responsible. This marked the first public attribution of the incident.
A ransomware attack hit Synnovis, a pathology services provider for several London NHS hospitals and GP practices, causing major disruption to diagnostics and treatment services. The incident affected hospitals including King's College Hospital and Guy's and St Thomas'.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
4 references tracked. Mallory keeps watching after this page renders.
bbc.co.uk
Open sourcecomputerweekly.com
Open sourcetherecord.media
Open sourcetelegraph.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.