Skip to content
City PM
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
Wednesday 28 May 2025 3:31 pm

NHS patient data at risk in major cyber attack

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
AI and security
AI security

A newly uncovered cyber attack has exposed sensitive information at two major NHS trusts, raising fears that patient records could be at risk.

Experts have warned that the hack, linked to a vulnerability in widely used mobile management software, marks a growing threat to critical UK infrastructure.

University College London hospitals, NHS Foundation Trust, and University Hospital Southampton, NHS Foundation Trust were among the victims identified in a widespread cyber breach analysed by cybersecurity firm EclecticIQ.

The company have said hackers exploited a security flaw in Ivanti Endpoint Manager Mobile, or EPMM, which manages work phones to gain clandestine access to trusted systems.

Cyber attack exploits vulnerability

Unlike the recent wave of cyber attacks on British retail, the breach appears to have involved the quiet extraction of data through a remote code execution vulnerability.

The flaw was discovered on May 15th and has since been patched by Ivanti; however, experts have warned that systems already compromised may still be vulnerable.

Cody Barrow, chief executive of EclecticIQ an former US cyber command adviser, told Sky News the hack presents an “urgent wake up call” for the NHS.

“The potential compromise scope goes well beyond data theft. We’re looking at the risk of unauthorised access to highly sensitive patient records, disrupted appointments, and even interference with critical medical devices”, he said.

Read more

Jaguar Land Rover eyes cost-cutting and wealthy buyers in cyber attack recovery

JLR logo prominently displayed in an automotive business setting, highlighting the companys brand presence and identity

According to EclecticIQ, affected data includes staff phone numbers, as well as authentication tokens – details which could be used to access deeper into trust networks.

The attackers have not been formally identified, but the firm said the use of an IP address in China and the tactics performed suggest links to previous China-based cyber actors.

NHS England investigates

NHS England confirmed it is investigating the incident with the National Cyber Security Centre (NCSC) and said its high-severity alert system had been activated to support trusts in affected systems.

“We provide 24/7 cyber monitoring and response across the NHS”, a spokesperson said.

The breach is the latest in a seemingly unstoppable string of cyber incidents targeting UK firms.

In the last couple of months, big, household names like Co-op, M&S, Harrods and – only yesterday – Adidas, have confirmed breaches on their systems.

Experts say the string of breaches highlights a widening threat landscape across the nation, with healthcare now firmly in the crosshairs.

Read more

The Debate: Should CEOs be held personally accountable for cyberattacks?

Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech
  • Business

People & Organisations

  • cyber attack
  • cyber security
  • data breach
  • NHS
  • nhs trust
  • patient data
  • uk business

Trending Articles

  • Revealed: Secret Treasury plan to tax State Pension before it is paid out

  • Two solicitors linked to Post Office scandal charged with misconduct

  • Burnham’s new chief of staff ran City firm advising Thames Water and rival Heathrow bidder

  • Barclays and Lloyds join banking sector plan for digital ID

  • Reeves’ new tax charge on cash ISAs faces fierce industry backlash

More from City PM

  • Jaguar Land Rover eyes cost-cutting and wealthy buyers in cyber attack recovery

    Retail
    JLR logo prominently displayed in an automotive business setting, highlighting the companys brand presence and identity
  • The Debate: Should CEOs be held personally accountable for cyberattacks?

    Opinion
    Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.
  • Gambit Cyber Launches Vizier AI – An Autonomous Security Intelligence Workspace for Continuous Exposure Management

    Business Wire
  • Harley Street Health District Releases First Annual Impact Report

    Business Wire
  • ‘Act now’: AI models capable of attacks on governments months away, Five Eyes warn

    Tech
    GettyImages 158774123 showcases a relevant business meeting scene, highlighting diverse professionals engaged in discussion.
  • Starmer scrambles to make savings in bid to boost defence spending

    Politics
    Keir Starmer discussing UKs defense strategy with BAE Systems executives in a formal meeting setting
  • Trump to reject UK plea over Anthropic ban as AI ‘kill switch’ fears grow

    Tech
    Getty Images logo on a modern office building exterior, symbolizing global influence in media and stock photography industry
  • Regulator wins decade-long pricing tussle with Pfizer

    Legal
    Hikma reported a jump in profit for 2024

City PM — European politics, business and analysis.

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Topics

  • Business
  • Markets
  • AI
  • Technology
  • Opinion
  • Energy

More

  • Politics
  • Economics
  • Fintech
  • Legal
  • Sport
  • Life

Company

  • About City PM
  • Contact
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 City PM. All rights reserved.
About · Contact · Terms · Privacy