← All Incident Reports
Incident report · TESSOC: Cyber / Organised Crime
Healthcare - supply chain

Synnovis: the supplier that stopped the blood

A criminal ransomware group encrypted a pathology provider serving south-east London. Hospitals lost blood matching, fell back on O-negative for everyone, and drained the national supply. Over 10,000 appointments and 1,710 operations were cancelled.

A year later an NHS trust confirmed that a long wait for a blood test result, caused by the attack, was one of the factors that led to a patient's death. This is the clearest answer available to anyone who still treats ransomware as an IT problem.

↓  Download one-page brief (PDF)
Who
Actor: Qilin, a Russian-speaking criminal ransomware group, which claimed the attack. This is organised crime for profit, not a state operation. Victim: Synnovis, a pathology partnership between Guy's and St Thomas' NHS Foundation Trust, King's College Hospital NHS Foundation Trust and SYNLAB. Casualties: one patient death, to which the disruption was a contributing factor; 170 patients recorded as harmed, most categorised as low harm.
What
A ransomware attack that affected almost all Synnovis IT systems, with data exfiltrated before encryption. A ransom reported at 50 million US dollars was demanded and not paid; around 400 GB of stolen data was published.
Where
Pathology services across south-east London - King's College Hospital, Guy's and St Thomas', Lewisham and Greenwich, and GP practices - with the blood supply consequence reaching nationwide.
When
3 June 2024. Data published on 20 June 2024. The patient death was confirmed by King's College Hospital NHS Foundation Trust in June 2025. Synnovis completed its forensic review in November 2025.
Why
Financial extortion. Qilin publicly characterised the action as political protest while declining to accept blame, but the mechanism was a ransom demand.
How
Systems encrypted after exfiltration. Without pathology, trusts could not perform blood matching, so they issued O-negative - the universal type - to everyone, which drained local stocks and then national ones.
What happened
1

3 June 2024 - encryption

Qilin encrypts Synnovis systems after stealing data. Almost all IT systems are affected and pathology services across multiple trusts stop.

2

Blood matching fails

Unable to match blood, hospitals fall back on O-negative for every transfusion. Local stocks deplete and the shortage spreads nationally, with a public appeal for donors.

3

The clinical toll

More than 10,000 outpatient appointments and 1,710 operations are cancelled across King's College Hospital and Guy's and St Thomas'. Recovery runs for months rather than weeks.

4

20 June 2024 - publication

With the ransom refused, Qilin publishes around 400 GB of stolen data, reported to include names, dates of birth, NHS numbers and pathology forms, and to name patients with cancer and with sexually transmitted infections.

5

June 2025 - a death confirmed

King's College Hospital NHS Foundation Trust completes a patient safety investigation into a death during the incident. It identifies several contributing factors, including a long wait for a blood test result caused by the attack, and shares the findings with the family.

Impact
Human
One death to which the attack contributed, and 170 patients recorded as harmed. Cancellation of 1,710 operations and more than 10,000 appointments carries its own clinical cost that is harder to count.
Operational
The failure was not of a hospital but of a supplier to hospitals. Losing one pathology partnership removed blood matching across several major trusts at once, and the workaround consumed a scarce national resource.
Data
Around 400 GB published, reported to relate to more than 900,000 patients, including cancer and sexual health information. Synnovis took over a year to complete its review because the stolen data was unstructured, incomplete and fragmented.
Financial
Synnovis reported the attack cost more than 32 million pounds. The ransom demand was reported at 50 million US dollars and was not paid.
Why a pathology lab was the single point of failure
The structure

One supplier, several trusts

Synnovis provides pathology to multiple large trusts under a partnership model. Efficient, and a single dependency shared by all of them.

The function

Blood matching is not optional

Transfusion requires typing and cross-matching. Without the laboratory there is no safe alternative except universal-donor blood, which is the scarcest type.

The consequence

A local outage became a national shortage

Falling back on O-negative for every patient at several major hospitals depleted the type most needed for emergencies everywhere else.

This is what makes the case worth studying rather than simply deploring. The attack hit a laboratory, and the harm landed on the national blood supply. No risk assessment written at the hospital boundary would have found that path, because the dependency ran through a supplier and out the other side into a shared resource nobody owned.

Assessment
1

Criminal, not state - and the outcome was worse than most state operations

Qilin is a profit-driven criminal group. Nothing in this incident required state sponsorship, and the harm exceeded that of every state-linked incident elsewhere in this library. Organised crime deserves to be treated as a first-order threat to critical services rather than as a lesser category.

2

The dependency was a supplier, and the harm was clinical

Boards routinely treat suppliers as a procurement matter and cyber risk as a technology matter. Here the two combined into a patient safety incident. Supplier failure modes belong in clinical risk registers, not only in IT ones.

3

Refusing the ransom was right, and the data was still published

The ransom was not paid and 400 GB was published, including some of the most sensitive categories of health data. Both things are true at once, and a plan that assumes payment prevents publication is not a plan.

4

Attribution to harm took a year, and needed a safety investigation

The link between the attack and the death was established by a patient safety incident investigation, not by a security process. Where services are safety-critical, the harm from a cyber incident will surface through clinical governance, and the two functions need to be talking.

5

The sector is the softest target with the highest stakes

Healthcare combines almost no tolerance for downtime, deep dependence on a small number of suppliers, and data worth publishing. That combination is exactly what extortion selects for, and none of it is going to change. It is almost certain that criminal groups continue to target healthcare providers and their suppliers in the UK, and the lesson here is that the damage arrives through the supplier rather than at the front door.

The number that matters

More than 10,000 appointments and 1,710 operations cancelled, 170 patients harmed, one death contributed to, a national blood shortage, over 32 million pounds in cost - from a criminal group encrypting a laboratory. No missile, no drone, no intelligence officer.

What should carry
  • Identify suppliers whose failure is clinical, not commercial. Pathology, imaging, pharmacy and patient records are not back-office functions. Map which suppliers stop care rather than stop invoicing.
  • Test the manual fallback honestly. The fallback here worked and consumed a national resource. A workaround that cannot be sustained for months is a bridge, not a plan.
  • Rehearse a supplier outage, not just your own. Most exercises assume the organisation is the victim. Run one where a supplier is dark for eight weeks and you have no visibility into their recovery.
  • Assume exfiltration precedes encryption. Data was stolen before systems were locked, so restoration from backup solved availability and nothing else. Notification, regulatory and duty-of-candour obligations start regardless.
  • Connect security incident management to clinical governance. The death here was found through a safety investigation. If those processes do not speak to each other, the harm is invisible to the people managing the incident.
  • Do not let "criminal" mean "lower priority". Judge threats by the consequence they can impose, not by the flag they operate under.
Sources

Compiled from open-source reporting for professional security discussion. This is a protective-security lessons-learned assessment, not an operational account.