Attribution in ransomware attack London hospitals: Qilin ransomware gang
A ransomware attack by the Qilin gang hit Synnovis, a pathology services provider, affecting major NHS hospitals in London, including Guy's and St Thomas' NHS Foundation Trust and King's College Hospital NHS Foundation Trust. The attack, linked to the Russian cybercriminal group Qilin, resulted in Synnovis being locked out of its systems, causing significant service disruptions. Non-emergency pathology appointments, blood transfusions, and surgeries have been postponed or redirected, although urgent and emergency services remain operational. The NHS is assessing the impact on patient and employee data.
The Qilin ransomware operation, previously known as "Agenda," has been active since August 2022, targeting companies by infiltrating networks, extracting data, and deploying ransomware to encrypt devices. They leverage the stolen data for double-extortion attacks, demanding ransoms from $25,000 to millions. The Qilin gang has developed advanced Linux encryptors to target VMware ESXi virtual machines.
Despite the ongoing issues, Qilin's dark web leak site is currently down, with no evidence linking this outage to the Synnovis attack.
Source: Qilin ransomware gang linked to attack on London hospitals
#Attribution #Qilin_ransomwareGang #London #hospitals #ransomware #Synnovis