• Wion
  • /World
  • /Russian group behind ‘very serious’ ransomware attack that impacted London hospital services

Russian group behind ‘very serious’ ransomware attack that impacted London hospital services

Russian group behind ‘very serious’ ransomware attack that impacted London hospital services

NHS

The former chief executive of the National Cyber Security Centre (NCSC) on Wednesday (June 5) said that a group of Russian cybercriminals is behind the ransomware attack that halted operations and tests in the major state-run National Health Service (NHS) in London.

The delivery of services at some of London's busiest hospitals was impacted significantly on Tuesday by a ransomware incident, the region's health service said. In a statement, a spokesperson for the NHS England London region said that Synnovis, a provider of lab services, was the victim of the incident on Monday.

Add WION as a Preferred Source

"This is having a significant impact on the delivery of services at Guy's and St Thomas', King's College Hospital NHS Foundation Trusts and primary care services in south east London," the statement added.

The health services earlier said that it was working "urgently" with the NCSC and its own cyber operations team to fully understand the impact of the incident. NCSC is the country's main cyber security agency.

Meanwhile, Ciaran Martin, the former chief executive of NCSC, said that the attack on pathology services firm Synnovis had led to a "severe reduction in capacity". He added that it was a "very, very serious incident".

During BBC Radio 4's Today programme, he was asked about the cyber attacks and whether or not he knew about them. He said, "Yes. We believe it is a Russian group of cybercriminals who call themselves Qilin."

"These criminal groups – there are quite a few of them – they operate freely from within Russia, they give themselves high-profile names, they've got websites on the so-called dark web, and this particular group has about a two-year history of attacking various organisations across the world. They've done automotive companies, they've attacked the Big Issue here in the UK, they've attacked Australian courts. They're simply looking for money."

Watch:Britain's Sunak and Starmer go head-to-head about the economy on a TV debate

During the show, he explained that there are two types of ransomware attacks. One is when the attackers steal a load of data with the objective of extorting money. But he said that the case with NHS was different as it's a "more serious" type of ransomware where the system just doesn't work.

"So, if you're working in healthcare in this trust, you're just not getting those results so it's actually seriously disruptive," he said, further adding that the government had a policy of not paying but the company would be free to pay the ransom if it chose to.

"The criminals are threatening to publish data, but they always do that. Here, the priority is the restoration of services," he added.

(With inputs from agencies)