NHS trusts targeted in ransomware strikes
One in seven trusts in England hit by extortion attempts
Cyber criminals have targeted at least 28 NHS England trusts with ransomware in the last 12 months, according to newly released figures.
The rate of attacks was revealed to the i newspaper following a Freedom of Information (FoI) request by cybersecurity firm NCC Group, with up to four being considered serious enough "they had to be reported as a potential breach of data protection or confidentiality laws".
While only around 14% of the total number of NHS trusts in England were affected, millions of patients' data were potentially at risk. However, no ransom was ever paid and no data ever lost, according to NHS Digital, the body which oversees cybersecurity for the health service.
Ollie Whitehouse, technical director of NCC Group, told i: "Ransomware has become the bottom line of cybercrime if hackers break into a system and can't find any other way to monetise what they find, they encrypt the data and demand a ransom. We have seen a 400% increase in these attacks.
"The health service is by no means alone in facing this kind of attack. But NHS trusts are being increasingly targeted and any loss of patient data would be a nightmare scenario. Like everyone else, they need to be applying robust controls."
In a statement to i, NHS Digital said: "Incidents are rare and in the last year there have been fewer than five reports of ransomware attacks on individual machines on a network used by around two million people. In all reported cases, effective and swift action was taken and no ransoms have been paid.
"Like all organisations the NHS is subject to malicious attacks on its systems and, like all organisations, these attempted attacks are rising. But we are taking action to ensure information is as safe as possible."
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
The OpenAI and Anthropic containment breaches are a bit spooky, but also quite sillyOpinion An AI leaving notes to future versions of itself is pure sci-fi; forgetting to lock down an environment is prosaic
-
Bringing data to the heart of AISponsored AI is changing our approach to data, find out how HPE Alletra Storage can help your business
-
Companies are still paying ransoms to cyber criminals despite official adviceNews A Proofpoint survey found evolving ransomware techniques and the use of AI is exacerbating the situation for victims
-
This one cyber crime group accounted for nearly a fifth of all ransomware attacks in JuneNews The Gentlemen, a ransomware a service operator, now accounts for 17% of published attacks
-
Working with the enemy: Ransomware negotiator-turned cyber criminal jailed after working with hackers to extort clientsNews Angelo Martino was supposed to be negotiating on behalf of victims, but was secretly working for ransomware operators
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Every hour ransomware goes undetected drastically increases its potential blast radius’: Hackers are breaching networks and laying low for longer – and nearly half of firms don’t realize until data is stolenNews An ExtraHop survey found more intrusions are going undetected, leading to longer dwell times
-
Ransomware cartels are fragmenting into volatile splinter groups, warns Met Police cyber chiefNews Commoditized "cyber crime bazaars" and AI data mining are forcing law enforcement to rewrite its playbook
-
New ransomware threat group, The Gentlemen, has become one of the most active ransomware operators, accounting for 10% of all attacksNews NTT researchers warn that the RaaS group is leveraging SystemBC malware to establish covert tunnelling, evade detection, and support rapid lateral movement across enterprise environments
-
Instructure chose to a pay ransom following the Canvas cyber attack – research shows more than half of security leaders would follow suitAnalysis Opting to pay ransoms creates huge risks for enterprises – you’re relying on the word of criminals