Patient data from NHS Dumfries and Galloway has been released on the dark web after a ransomware group threatened to share the large volume of data after a cyber-attack in March.
Back in March, a small amount of information was shared by the ransomware group as proof their their cyber-attack successfully accesses patient data. They had warned at the time that more confidential data would be released if a ransom was not paid.
The ransomware group claiming responsibility, Inc Ransom, have now owned up to the threat, releasing data on the dark web.
This release of data follows a sustained cyber campaign by the threat actors which interrupted the NHS region’s IT system from 15 March. Services were back up by 19 March, but it was not until 27 March that a small number of patient data was published by a ransomware group.
According to updates on the NHS Dumfries and Galloway site, the sustained cyber-attack began in February, and accessed a very large amount of patient and staff data.
“This is an utterly abhorrent criminal act by cyber criminals who had threatened to release more data,” NHS Dumfries and Galloway chief executive Julie White said.
“Work is beginning to take place with partner agencies to assess the data which has been published. This very much remains a live criminal matter, and we are continuing to work with national agencies including Police Scotland, the National Cyber Security Centre and the Scottish Government.”
Recommended reading
- OpenAI & Microsoft Disrupt State-backed Hackers
- NHS Scotland Confirms Data Theft
- Warning Issued Over North Korean Threat Actors Posing as IT Workers
The health board noted the anxiety this breach may be causing patients, but urged people to remain vigilant as their data may have been shared on the dark web.
A dedicated helpline is now open to the public (01387 216 777), and ongoing updates on the situation can be found here.
“Data accessed by the cyber criminals has now been published onto the dark web – which is not readily accessible to most people,” White added.
“Recognising that this is a live criminal matter, we continue to follow the very clear guidance being provided to us by national law enforcement agencies.”
Jude McCorry, CEO of Cyber and Fraud Centre – Scotland, said: “It is truly awful that patient data has now been released in the NHS Dumfries and Galloway cyber attack. This will understandably be hugely concerning to patients, and we would encourage anyone affected to follow the health board’s advice and be alert to any approaches by anyone claiming to have your personal or NHS data, and report to Police Scotland.
“We are also asking people not to share any personal data that may make its way onto different forms of social media, in relation to the attack over the next few weeks.
“This attack further emphasises the sophistication of ransomware groups, and we would urge any organisations in Scotland that need support to mitigate the impacts of an attack, to contact our free Incident Response helpline on 0800 167 0623. Our team can give expert guidance to help you resume operations.
“If you are concerned your organisation has been the victim of a cyber attack or data breach, please ensure that you report the incident to Police Scotland on 101. If you are an individual and think your data may have been stolen in a data breach, you can take some simple steps to mitigate the impact such as being alert to phishing attacks, safeguarding other online accounts and monitoring your bank account for suspicious activity.”





