A hacking gang from Russia is behind the ransomware attack that disrupted operations at major NHS , the former chief executive of the National Cyber Security Centre has said.

Ciaran Martin said the attack on pathology services company Synnovis had led to a “severe reduction in capacity” and was a “very, very serious incident”.
Read more: Major London hospitals affected by ransomware
Hospitals declared a critical incident after the ransomware attack and canceled surgeries and tests and were unable to perform blood transfusions.
Memos to NHS staff at King's College Hospital, Guy's and St Thomas' (including the Royal Brompton Children's Hospital and Evelina London) and primary care services in the capital said there had been a "major IT incident".
Asked on BBC Radio 4's Today show on Wednesday whether it was known who attacked Synnovis, Martin said: "Yes. We believe it's a Russian cybercriminal group calling themselves Qilin.
"These criminal groups – there are several – operate freely from Russia, they give high-profile names, they have websites on the so-called dark web , and this particular group has about a two-year history of attacks on various organizations around the world.
"They've done car companies, they've attacked the Big Issue here in the UK, they've attacked Australian courts. They're just looking for money.".
He said it was unlikely that the Russian hackers knew they would cause such a serious disruption to primary healthcare when they launched the attack.
He added: "There are two types of ransomware attacks. One is when they steal data and try to blackmail you into paying to keep it from being released, but this case is different. It's the most serious type of ransomware where the system simply doesn't work.
See also: Hackers target Russia with Decoy Dog malware
"So if you work in healthcare, you just don't get those results, which is really annoying.".
He said the government had a policy of not paying, but the company would be free to pay the ransom if it chose to.
"Criminals threaten to release data, but they always do. Here, the priority is to restore services.".
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
The National Cyber Security Centre is investigating the impact of the cyberattack alongside NHS officials.
Synnovis said the incident was reported to the police and the information commissioner.
Health Secretary Victoria Atkins wrote to X on Wednesday: "Over the course of yesterday I held meetings with NHS England and the National Cyber Security Centre to oversee the response to the cyberattack on pathology services in south-east London. My absolute priority is safety and the safe resumption of services in the coming days."

See more: Ransomware gang leaks LAUSD school system data
Synnovis chief executive Mark Dollar said a team of IT experts from Synnovis and the NHS were working to fully assess the impact and action required.
Source: theguardian
