UPDATE: Dumfries and Galloway Health Board has confirmed that it is aware that clinical data related to a small number of patients is being published by a ransomware group.
In a statement, NHS Dumfries and Galloway chief executive Jeff Ace said: “We absolutely deplore the release of confidential patient data as part of this criminal act.
“This information has been released by hackers to evidence that this is in their possession.
“We are continuing to work with Police Scotland, the National Cyber Security Centre, the Scottish Government, and other agencies in response to this developing situation.
“Patient-facing services continue to function effectively as normal.
“As part of this response, we will be making contact with any patients whose data has been leaked at this point, and continue working to limit any sharing of this information.
“NHS Dumfries and Galloway is very acutely aware of the potential impact of this development on the patients whose data has been published, and the general anxiety which might result within our patient population.”
Earlier today (27 March), ransomware group Inc Ransom threatened to publish three terbytes of data from NHS Scotland, detailed below.
In an update to the Dumfries and Galloway data breach story, a ransomware group has claimed responsibility for the recent cyber-attack, claiming they have stolen three terabytes of data from the NHS Scotland board.
This is according to a new post from DarkWebInformer, which shows the ransomware gang Inc Ransom stating they will publish three terabytes of data from the NHS Scotland health board.
The post does not disclose what specific health boards the data is sourced from, so it is currently uncertain if the data is related to the recent Dumfries and Galloway health board data breach, or if other NHS Scotland boards were affected.
The price being demanded for the three terabytes of data is not yet known, and it is currently unconfirmed if the group actually has access to data, of if the data is of a personal nature.
In a statement to DIGIT during the early hours of the attack, the Dumfries and Galloway Health Board told DIGIT that that the hackers could have acquired a “significant quantity of data,” and that the board has “reason to believe that this could include patient-identifiable and staff-identifiable data.”
⚠️#BREAKING Allegedly, #INCRANSOM has named a new victim.#Ransomware #DarkWebInformer #DarkWeb #Cybersecurity #Cyberattack #Cybercrime #Infosec #CTI
Country: #UK🇬🇧
Threat Actor: INC RANSOM
Company: NHS Scotland
Industry: Federal
Revenue: $17.8 Billion
Data Stolen: 3TB
Price:… pic.twitter.com/nySTqoMGRz— Dark Web Informer (@DarkWebInformer) March 26, 2024
While health secretary Neil Gray was able to later assure the public that the attack had minimal interruption on patient services, he did confirm that a significant amount of patient and staff data could have been accessed





