Site navigation

NHS Scotland Confirms Data Theft

Elizabeth Greenberg

,

nhs scotland data breach
A ransomware group has alleged it has three terabytes of NHS Scotland health board data it threatens to release. 

UPDATE: Dumfries and Galloway Health Board has confirmed that it is aware that clinical data related to a small number of patients is being published by a ransomware group.

In a statement, NHS Dumfries and Galloway chief executive Jeff Ace said: “We absolutely deplore the release of confidential patient data as part of this criminal act.

“This information has been released by hackers to evidence that this is in their possession.

“We are continuing to work with Police Scotland, the National Cyber Security Centre, the Scottish Government, and other agencies in response to this developing situation.

“Patient-facing services continue to function effectively as normal.

“As part of this response, we will be making contact with any patients whose data has been leaked at this point, and continue working to limit any sharing of this information.

“NHS Dumfries and Galloway is very acutely aware of the potential impact of this development on the patients whose data has been published, and the general anxiety which might result within our patient population.”

Earlier today (27 March), ransomware group Inc Ransom threatened to publish three terbytes of data from NHS Scotland, detailed below.

In an update to the Dumfries and Galloway data breach story, a ransomware group has claimed responsibility for the recent cyber-attack, claiming they have stolen three terabytes of data from the NHS Scotland board.

This is according to a new post from DarkWebInformer, which shows the ransomware gang Inc Ransom stating they will publish three terabytes of data from the NHS Scotland health board.

The post does not disclose what specific health boards the data is sourced from, so it is currently uncertain if the data is related to the recent Dumfries and Galloway health board data breach, or if other NHS Scotland boards were affected.

The price being demanded for the three terabytes of data is not yet known, and it is currently unconfirmed if the group actually has access to data, of if the data is of a personal nature.

In a statement to DIGIT during the early hours of the attack, the Dumfries and Galloway Health Board told DIGIT that  that the hackers could have acquired a “significant quantity of data,” and that the board has “reason to believe that this could include patient-identifiable and staff-identifiable data.”

While health secretary Neil Gray was able to later assure the public that the attack had minimal interruption on patient services, he did confirm that a significant amount of patient and staff data could have been accessed

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data