iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The June 2024 ransomware attack on Synnovis, a pathology-services provider for NHS organisations in London, disrupted laboratory testing and contributed to cancelled or redirected care. In June, authorities were checking files criminals said they had published online; Synnovis later said its forensic investigation ended by late summer 2025. The attack was attributed in contemporaneous reporting to the Qilin group, but that reported assessment does not establish Russian state involvement.
What happened in the Synnovis cyberattack?
On 3 June 2024, ransomware disrupted Synnovis’s IT systems and pathology services. Synnovis provides laboratory services to NHS organisations, including King’s College Hospital and Guy’s and St Thomas’ trusts. The incident targeted this pathology provider; it was not described as a general breach of hospital clinical systems.
| # | Preview | Product | Price | |
|---|---|---|---|---|
| 1 |
|
Smart Keeper USB-C Port Locks with Key, 4 Blockers 1 Key | $34.82 | Buy on Amazon |
Pathology testing capacity was affected, with reports of cancelled or redirected appointments and procedures. Blood-transfusion services were among the areas experiencing particular disruption. Ciaran Martin, former chief executive of the UK National Cyber Security Centre, told the Associated Press: “If you’re working in healthcare in this trust, you’re just not getting those results so it’s actually seriously disruptive.” Associated Press, June 5, 2024.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Who was believed to be responsible?
In June 2024, the Associated Press reported that the Qilin group was believed responsible. AP described Qilin as a Russian cyber gang, but the reporting does not establish that the attack was directed by the Russian state. The attribution should therefore be understood as a reported assessment, not proof of state sponsorship. Associated Press, June 5, 2024.
#1 Best Overall
- Bundle: 4 locks + 1 key.
- Easy to Use: It can be installed by hand.
- All-Purpose Key: A common key can be used to unlock 9 different products within the Essential series.
Was patient data published online?
By 20 June 2024, Synnovis said criminals had published stolen data. NHS England said the National Crime Agency (NCA) and National Cyber Security Centre (NCSC) were checking files reported as published. The existence of a reported online release is distinct from confirmation of exactly what it contained or how many people were affected; the available reporting does not establish a definitive total of affected people.
Synnovis later said the stolen data came from working drives and that no data was taken from its primary laboratory databases. That is Synnovis’s account, not an independently established finding presented here. Synnovis incident update.
How long did the investigation take?
In June 2024, NHS England warned that verifying the published files could take weeks or longer. It told the Associated Press: “These files are not simple uploads and so investigations of this nature are highly complex and can take weeks if not longer to complete.” That was an estimate of the work ahead at the time, not a statement that the investigation was still open indefinitely. Associated Press, June 22, 2024.
Synnovis subsequently reported that its forensic investigation concluded by late summer 2025. It also said it had finished notifying affected organisations by the end of November 2025. These are separate milestones: the first concerns Synnovis’s forensic review, while the second concerns notices to organisations whose data was affected. Synnovis incident update.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Have all affected patients been notified?
Not necessarily. Synnovis says it will not directly contact impacted patients; affected healthcare organisations are responsible for deciding whether and when patients should be notified. Synnovis’s report that it notified affected organisations does not mean every patient has received notice or that every organisation has completed its assessment. Patients with concerns should use the contact or data-protection information provided by their own NHS organisation. Synnovis incident update.
Quick Recap
Synnovis attack timeline
| Date | What was reported |
|---|---|
| 3 June 2024 | Ransomware affected Synnovis IT systems and interrupted pathology services, according to Synnovis. |
| June 2024 | Contemporaneous reporting described cancellations and disruption; AP reported that Qilin was believed responsible. |
| By 20 June 2024 | Synnovis said criminals had published stolen data. |
| 22 June 2024 | NHS England said checking reported published files could take weeks or longer. |
| Late summer 2025 | Synnovis said its forensic investigation had concluded. |
| End of November 2025 | Synnovis said it had completed notifying affected organisations; those organisations decide on patient notifications. |
| March 2026 update | Synnovis reiterated that affected healthcare organisations, rather than Synnovis, determine patient notification. |
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

