Synnovis, the UK pathology service provider which faced a ransomware attack in June 2024 is now notifying healthcare providers of the data breach and patient data theft that resulted from the attack.
The London-based provider has partnerships with the National Health Service, SYNLAB, Guy’s and St Thomas’ NHS Foundation Trust, and King’s College Hospital NHS Foundation Trust.
It is reaching out to affected organisations, which will then contact affected patients who have had their data stolen.
“We have now begun notifying the organisations whose data was affected and expect to conclude this process by 21 November 2025,” Synnovis said in an update.
“This marks the latest stage of investigation that has taken a large team of forensic experts and data specialists over a year to complete”
It described the stolen data as “unstructured, incomplete and fragmented, requiring the use of highly specialised platforms and bespoke processes to piece it together – factors which heavily influenced the duration of the investigation.”
Recommended reading
- New Bill Targets Cyber Threats to UK Infrastructure
- NHS Scotland Invests £3M in AI Anti-ransomware Software
- UK Facing 4 Major Cyber-Attacks Each Week, Warns NCSC
Stolen data includes NHS numbers, patient names, dates of birth, and even test results that can be matched to other data. Synnovis has, however, assured that the majority of the data would require “clinical knowledge” to decipher further.
The 2024 ransomware attack left a “major impact” on Synnovis’s operations, as many appointments and blood transfusions across London hospitals were cancelled or rerouted through other providers. London even faced blood shortages due to the operational impact, highlighting the devastating impact ransomware can have on critical infrastructure such as health.
While Synnovis has not named the group behind the ransomware attack, Ciaran Martin, the founder and first CEO of the National Cyber Security Centre linked the attack to Qilin, the ransomware group with ties to Russia.
While this has yet to be officially confirmed, Synnovis did say that it did not pay any ransom for the data.





