Synnovis: the supplier that stopped the blood
A criminal ransomware group encrypted a pathology provider serving south-east London. Hospitals lost blood matching, fell back on O-negative for everyone, and drained the national supply. Over 10,000 appointments and 1,710 operations were cancelled.
A year later an NHS trust confirmed that a long wait for a blood test result, caused by the attack, was one of the factors that led to a patient's death. This is the clearest answer available to anyone who still treats ransomware as an IT problem.
↓ Download one-page brief (PDF)3 June 2024 - encryption
Qilin encrypts Synnovis systems after stealing data. Almost all IT systems are affected and pathology services across multiple trusts stop.
Blood matching fails
Unable to match blood, hospitals fall back on O-negative for every transfusion. Local stocks deplete and the shortage spreads nationally, with a public appeal for donors.
The clinical toll
More than 10,000 outpatient appointments and 1,710 operations are cancelled across King's College Hospital and Guy's and St Thomas'. Recovery runs for months rather than weeks.
20 June 2024 - publication
With the ransom refused, Qilin publishes around 400 GB of stolen data, reported to include names, dates of birth, NHS numbers and pathology forms, and to name patients with cancer and with sexually transmitted infections.
June 2025 - a death confirmed
King's College Hospital NHS Foundation Trust completes a patient safety investigation into a death during the incident. It identifies several contributing factors, including a long wait for a blood test result caused by the attack, and shares the findings with the family.
One supplier, several trusts
Synnovis provides pathology to multiple large trusts under a partnership model. Efficient, and a single dependency shared by all of them.
Blood matching is not optional
Transfusion requires typing and cross-matching. Without the laboratory there is no safe alternative except universal-donor blood, which is the scarcest type.
A local outage became a national shortage
Falling back on O-negative for every patient at several major hospitals depleted the type most needed for emergencies everywhere else.
This is what makes the case worth studying rather than simply deploring. The attack hit a laboratory, and the harm landed on the national blood supply. No risk assessment written at the hospital boundary would have found that path, because the dependency ran through a supplier and out the other side into a shared resource nobody owned.
Criminal, not state - and the outcome was worse than most state operations
Qilin is a profit-driven criminal group. Nothing in this incident required state sponsorship, and the harm exceeded that of every state-linked incident elsewhere in this library. Organised crime deserves to be treated as a first-order threat to critical services rather than as a lesser category.
The dependency was a supplier, and the harm was clinical
Boards routinely treat suppliers as a procurement matter and cyber risk as a technology matter. Here the two combined into a patient safety incident. Supplier failure modes belong in clinical risk registers, not only in IT ones.
Refusing the ransom was right, and the data was still published
The ransom was not paid and 400 GB was published, including some of the most sensitive categories of health data. Both things are true at once, and a plan that assumes payment prevents publication is not a plan.
Attribution to harm took a year, and needed a safety investigation
The link between the attack and the death was established by a patient safety incident investigation, not by a security process. Where services are safety-critical, the harm from a cyber incident will surface through clinical governance, and the two functions need to be talking.
The sector is the softest target with the highest stakes
Healthcare combines almost no tolerance for downtime, deep dependence on a small number of suppliers, and data worth publishing. That combination is exactly what extortion selects for, and none of it is going to change. It is almost certain that criminal groups continue to target healthcare providers and their suppliers in the UK, and the lesson here is that the damage arrives through the supplier rather than at the front door.
More than 10,000 appointments and 1,710 operations cancelled, 170 patients harmed, one death contributed to, a national blood shortage, over 32 million pounds in cost - from a criminal group encrypting a laboratory. No missile, no drone, no intelligence officer.
- Identify suppliers whose failure is clinical, not commercial. Pathology, imaging, pharmacy and patient records are not back-office functions. Map which suppliers stop care rather than stop invoicing.
- Test the manual fallback honestly. The fallback here worked and consumed a national resource. A workaround that cannot be sustained for months is a bridge, not a plan.
- Rehearse a supplier outage, not just your own. Most exercises assume the organisation is the victim. Run one where a supplier is dark for eight weeks and you have no visibility into their recovery.
- Assume exfiltration precedes encryption. Data was stolen before systems were locked, so restoration from backup solved availability and nothing else. Notification, regulatory and duty-of-candour obligations start regardless.
- Connect security incident management to clinical governance. The death here was found through a safety investigation. If those processes do not speak to each other, the harm is invisible to the people managing the incident.
- Do not let "criminal" mean "lower priority". Judge threats by the consequence they can impose, not by the flag they operate under.
- https://www.theregister.com/2025/06/26/qilin_ransomware_nhs_death/
- https://www.infosecurity-magazine.com/news/patient-death-linked-nhs-cyber/
- https://www.hipaajournal.com/patient-death-linked-to-ransomware-attack/
- https://www.theregister.com/2025/11/13/synnovis_qilin_investigation/
- https://www.govinfosecurity.com/breach-roundup-uk-nhs-links-patient-death-to-ransomware-attack-a-28836
Compiled from open-source reporting for professional security discussion. This is a protective-security lessons-learned assessment, not an operational account.