Synnovis oneof the largest pathology service providers in the United Kingdom, announced that it had suffered a data breach following a devastating ransomware that occurred in June 2024. According to the company, the investigation showed that some patient data was stolen, in an incident that seriously affected the operation of several major NHS.

From Viapath to Synnovis – A pivotal link for the NHS
Synnovis, known until 2022 as Viapath, is a joint venture between SYNLAB, the international medical diagnostics giant, and two of London's largest hospitals: Guy's and St Thomas' NHS Foundation Trust and King's College Hospital NHS Foundation Trust.
Since its founding in 2009 (then as GSTS Pathology), the company has played a central role in providing laboratory and pathology services to dozens of public health organisations in the UK. The 2024 attack revealed the vulnerability of critical healthcare, as well as the enormous challenges organisations face when faced with cybercriminal groups targeting patient data.
See also: 'Maverick' malware targets bank customers in Brazil via WhatsApp
Notifications begin – Patients are informed via the NHS
According to an official statement, Synnovis is in the process of notifying partner organizations – primarily NHS hospitals and clinics – whose data may have been affected. However, the company will not be contacting patients directly, as the notification process will be done through NHS organizations, in accordance with British data protection law.
Synnovis noted that the process will be completed by November 21, 2025, adding that the investigation took more than a year due to the complexity and fragmented nature of the stolen data. “The data was unstructured, incomplete and fragmented,” the company said, emphasizing that it required the use of specialized forensic tools to analyze and verify it.

What data was stolen?
Although the scope of the breach remains under assessment, the stolen data appears to include names, dates of birth, NHS numbers and – in some cases – medical test results that can be linked to specific individuals.
The company clarified, however, that "the majority of the information requires clinical knowledge or further enrichment to be valuable or interpreted correctly," attempting to allay concerns about a massive leak of sensitive medical data.
The Qilin attack and the domino effect on London hospitals
The cyberattack of June 3, 2024, had a "significant operational impact" on several of London's largest hospitals, including King's College Hospital, Guy's Hospital, St Thomas' Hospital, Royal Brompton Hospital and Evelina London Children's Hospital.
See also: CISO guide to supply chain attacks using AI
The disruption to pathology systems led to mass cancellations of appointments and procedures – more than 800 surgeries and 700 outpatient appointments were postponed or cancelled, while there were severe blood shortages in London hospitals.
The cyberattack was ultimately attributed to the gang Qilin, a ransomware-as-a-service (RaaS) organization that has been active since 2022 and has over 300 attacks worldwide. Qilin (formerly “Agenda”) has targeted large organizations such as Yangfeng Automotive and publishing group Lee Enterprises.

Ethical stance towards ransoms
Unlike other organizations, Synnovis and its NHS partners have decided not to pay the ransom, despite the enormous pressure caused by the attack. As stated in the official statement: “Our decision reflects our commitment to ethical principles and refusal to fund future cyberattacks that threaten critical infrastructure and patient safety.”
See also: Oracle EBS hack: GlobalLogic warns of data breach
☁️ Keep safe copies with Proton Drive
Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.
- ✔ End-to-end encrypted files & backups
- ✔ Version history — recover files after ransomware
- ✔ Free space — sync across all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
This stance highlights the difficulty healthcare organizations have in balancing data protection with avoiding reinforcing the criminal ransomware ecosystem.
A strong message about healthcare cybersecurity
The Synnovis case serves as a wake-up call for the UK healthcare system and for organisations that handle sensitive personal data. At a time when cyberattacks are becoming increasingly targeted, the need to invest in infrastructure security is more urgent than ever.
Source: www.bleepingcomputer.com
