NHS trusts targeted in ransomware strikes
One in seven trusts in England hit by extortion attempts


Cyber criminals have targeted at least 28 NHS England trusts with ransomware in the last 12 months, according to newly released figures.
The rate of attacks was revealed to the i newspaper following a Freedom of Information (FoI) request by cybersecurity firm NCC Group, with up to four being considered serious enough "they had to be reported as a potential breach of data protection or confidentiality laws".
While only around 14% of the total number of NHS trusts in England were affected, millions of patients' data were potentially at risk. However, no ransom was ever paid and no data ever lost, according to NHS Digital, the body which oversees cybersecurity for the health service.
Ollie Whitehouse, technical director of NCC Group, told i: "Ransomware has become the bottom line of cybercrime if hackers break into a system and can't find any other way to monetise what they find, they encrypt the data and demand a ransom. We have seen a 400% increase in these attacks.
"The health service is by no means alone in facing this kind of attack. But NHS trusts are being increasingly targeted and any loss of patient data would be a nightmare scenario. Like everyone else, they need to be applying robust controls."
In a statement to i, NHS Digital said: "Incidents are rare and in the last year there have been fewer than five reports of ransomware attacks on individual machines on a network used by around two million people. In all reported cases, effective and swift action was taken and no ransoms have been paid.
"Like all organisations the NHS is subject to malicious attacks on its systems and, like all organisations, these attempted attacks are rising. But we are taking action to ensure information is as safe as possible."
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives

Jane McCallion is Managing Editor of ITPro and ChannelPro, specializing in data centers, enterprise IT infrastructure, and cybersecurity. Before becoming Managing Editor, she held the role of Deputy Editor and, prior to that, Features Editor, managing a pool of freelance and internal writers, while continuing to specialize in enterprise IT infrastructure, and business strategy.
Prior to joining ITPro, Jane was a freelance business journalist writing as both Jane McCallion and Jane Bordenave for titles such as European CEO, World Finance, and Business Excellence Magazine.
-
Prolific ransomware operator added to Europe’s Most Wanted list as US dangles $10 million reward
News The US Department of Justice is offering a reward of up to $10 million for information leading to the arrest of Volodymyr Viktorovych Tymoshchuk, an alleged ransomware criminal.
-
Jaguar Land Rover “did the right thing” shutting down systems to thwart cyber attack
News The attack on Jaguar Land Rover highlights the growing attractiveness of the automotive sector
-
Ransomware attack on IT supplier disrupts hundreds of Swedish municipalities
News The attack on IT systems supplier Miljödata has impacted public sector services across the country
-
A notorious hacker group is ramping up cloud-based ransomware attacks
News The Storm-0501 threat group is refining its tactics, according to Microsoft, shifting away from traditional endpoint-based attacks and toward cloud-based ransomware.
-
Security researchers have just identified what could be the first ‘AI-powered’ ransomware strain – and it uses OpenAI’s gpt-oss-20b model
News Using OpenAI's gpt-oss:20b model, ‘PromptLock’ generates malicious Lua scripts via the Ollama API.
-
Data I/O shuts down systems in wake of ransomware attack
News Regulatory filings by Data I/O suggest the costs of dealing with the attack could be significant
-
Average ransom payment doubles in a single quarter
News Targeted social engineering and data exfiltration have become the biggest tactics as three major ransomware groups dominate
-
BlackSuit ransomware gang taken down in latest law enforcement sting – but members have already formed a new group
News The notorious gang has seen its servers taken down and bitcoin seized, but may have morphed into a new group called Chaos