Site navigation

Scottish Mental Health Charity Struck by “Sophisticated” Cyber-Attack

Ross Kelly

,

Scottish Association for Mental Health
SAMH Chief Executive Billy Watson described the incident as a “sophisticated and criminal cybersecurity attack.”

The Scottish Association for Mental Health (SAMH) has fallen victim to a cyber-attack which has severely disrupted IT services.

In a statement released on Thursday 17th March, the Glasgow-based charity revealed that email and phone services had been impacted.

“SAMH is currently dealing with an IT incident, which is affecting our colleagues’ ability to receive and respond to emails across both our national and local service locations. Some of our national phone lines are also affected,” the statement read.

According to reports from IT Pro, details of the attack were first revealed online by cybersecurity researcher, Sofiane Tahiri.

In a post on Twitter, Tahiri revealed they had discovered more than 12Gb of data belonging to the charity on the dark web.

Data exposed in the cyber-attack appears to include sensitive personal information such as names, addresses, email addresses and passport information.

SAMH Chief Executive Billy Watson confirmed the incident in a statement on Monday, describing it as a “sophisticated and criminal cybersecurity attack.”

“We are devastated by this attack. It is difficult to understand why anyone would deliberately try to disrupt the work of an organisation that is relied on by people at their most vulnerable,” he said.

“Our priority is to continue to do everything we can to deliver our vital services. My thanks to our staff team who, under difficult circumstances, are finding ways to keep our support services running to ensure those they support experience as little disruption as possible.”

SAMH provides critical mental health support for people across Scotland, working with young people and adults.

Watson revealed the organisation is responding to the attack and is in close communication with Police Scotland and “various agencies”.

Commenting on the incident, SBRC CEO Jude McCorry told DIGIT: “Any attack is horrific, but something like this will have a huge impact on an organisation who’s sole purpose is to help vulnerable people in Scotland.

“I would ask people to give the organisation space to deal with this criminal act and its impact to its staff and clients, and for this attack to act as a reminder to everyone in Scotland that no organisation is immune to this despicable criminal activity.”


Recommended


A cybercriminal gang behind the ‘RansomEXX’ strain of ransomware has since claimed responsibility for the attack, adding the charity to an extensive list of victims online.

RansomEXX has previously been used in a number of high-profile breaches, including attacks against government systems in both the United States and Italy.


Scot-Secure 2022 | Join the Conversation

Have you registered for a place at the 2022 Scot-Secure Summit? The 8th annual conference will be held live and in-person at Dynamic Earth in Edinburgh on 23rd March.

The programme will focus on promoting best-practice cybersecurity; looking at the current trends, key threats, and offering practical advice on improving resilience and implementing effective security measures.

To find out more and sign up for the event, click here.

Ross Kelly

Staff Writer & Researcher

Latest News

Cybersecurity

Scotland’s Prosecution Service Suffers Third-party Data Breach

AI Featured

Anthropic Eyes Record-Breaking $2tn IPO as It Invites Public to Ask ‘Hard Questions’

Editor's Picks Events Technology

TecTonic Night Summit Returns for Glasgow Tech Week 2026

Funding Infrastructure

UK Semiconductor Sector Reaches £237M in 2026 So Far