NHS supplier DXS International confirms cyber attack – here’s what we know so far
The NHS supplier says front-line clinical services are unaffected
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
NHS software supplier DXS International has disclosed a cyber attack on its internal systems.
The company provides clinical support solutions for clinical commissioning groups, doctors, nurses and pharmacists as part of their workflow and during patient consultations.
Its products integrate with core NHS systems, and in some cases are hosted on the NHS’ Health and Social Care Network (HSCN).
The company says it supports around 10% of all NHS referrals in England. Its ExpertCare solution, for example, helps clinicians quickly understand prescription needs for cardiovascular diseases, and is used by around 2,000 GPs, overseeing the care of around 17 million patients.
In a filing with the London Stock Exchange, DXS International said it had discovered a security incident affecting its office servers in the early hours of Sunday, 14 December.
"Once discovered, the data security breach was immediately contained by means of a joint effort by DXS’s internal IT security teams in close cooperation with NHS England," said the firm.
"The Board has appointed an external cyber security specialist agency whose thorough investigations are underway to establish the nature and extent of the incident."
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
The company said there's been "minimal" impact on its services, with front-line clinical services unaffected and operational.
DXS has notified the relevant regulators, authorities, and law enforcement agencies, including the Information Commissioner's Office (ICO), and is fully cooperating with their investigations. It's also working with various NHS bodies
“We, along with the National Cyber Security Centre and law enforcement partners, are working with an NHS supplier who is investigating a cyber incident," an NHS England spokesperson told ITPro. “We are not aware of any patient services being impacted.”
DXS International the latest NHS supplier hit
Attacks on NHS suppliers are becoming increasingly common, with threat actors viewing third-party providers as a potentially lucrative source of data.
Earlier this year, Birmingham-based software provider Advanced Computer Software Group was handed a £3 million fine by the Information Commissioner's Office (ICO) for security failings that led to a ransomware attack on the NHS.
In another example, thousands of procedures were canceled at London hospitals after an attack on blood testing company Synnovis. The attack was claimed by Russian-speaking ransomware group Qilin.
Last month, the government proposed new laws to strengthen cybersecurity in public services, including the NHS.
Medium and large companies providing services like IT management, IT help desk support, and cybersecurity will be regulated for the first time, required to report incidents promptly, and implement more robust recovery plans.
As a result, critical suppliers such as those providing healthcare diagnostics to the NHS will have to meet tighter security requirements, and enforcement will be toughened up.
"The reforms will make fundamental updates to our approach to addressing the greatest risks and harms, such as new powers to designate critical suppliers," said national chief information security officer for health and care at the Department of Health and Social Care, Phil Huggins.
"Working with the healthcare sector, we can drive a step change in cyber maturity and help keep services available, protect data, and maintain trust in our systems in the face of an evolving threat landscape."
FOLLOW US ON SOCIAL MEDIA
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
AutoCAD Users may have a ransomware problem – here's what they can doIn-depth A new malware family is currently using the same file types as the professional design software AutoCAD
-
Google Workspace just got a huge Gemini updateNews Google is targeting deeper Gemini integration across a range of Workspace applications
-
Using AI to generate passwords is a terrible idea, experts warnNews Researchers have warned the use of AI-generated passwords puts users and businesses at risk
-
Researchers called on LastPass, Dashlane, and Bitwarden to up defenses after severe flaws put 60 million users at risk – here’s how each company respondedNews Analysts at ETH Zurich called for cryptographic standard improvements after a host of password managers were found lacking
-
‘They are able to move fast now’: AI is expanding attack surfaces – and hackers are looking to reap the same rewards as enterprises with the technologyNews Potent new malware strains, faster attack times, and the rise of shadow AI are causing havoc
-
Ransomware gangs are using employee monitoring software as a springboard for cyber attacksNews Two attempted attacks aimed to exploit Net Monitor for Employees Professional and SimpleHelp
-
Notepad++ hackers remained undetected and pushed malicious updates for six months – here’s who’s responsible, how they did it, and how to check if you’ve been affectedNews Hackers remained undetected for months and distributed malicious updates to Notepad++ users after breaching the text editor software – here's how to check if you've been affected.
-
CISA’s interim chief uploaded sensitive documents to a public version of ChatGPT – security experts explain why you should never do thatNews The incident at CISA raises yet more concerns about the rise of ‘shadow AI’ and data protection risks
-
Former Google engineer convicted of economic espionage after stealing thousands of secret AI, supercomputing documentsNews Linwei Ding told Chinese investors he could build a world-class supercomputer
-
90% of companies are woefully unprepared for quantum security threats – analysts say they need to get a move onNews Quantum security threats are coming, but a Bain & Company survey shows systems aren't yet in place to prevent widespread chaos
