In June 2024, a ransomware attack on Synnovis, a key UK pathology services provider, disrupted critical healthcare operations across London. The incident, linked to the Qilin ransomware gang, led to the theft of sensitive patient data, including NHS numbers, names, dates of birth, and some test results. More than a year later, in November 2025, Synnovis began notifying affected organizations—a reminder of just how long the tail on these breaches runs. It's a case study in healthcare supply-chain fragility and in how ransomware crews keep shifting tactics.

Ransomware Strike Paralyzes London Hospitals
The attack hit on June 3, 2024, crippling pathology services at major NHS hospitals: King's College, Guy's, St Thomas', Royal Brompton, and Evelina London Children's Hospital. Non-emergency procedures, including blood transfusions and over 800 planned operations, were canceled or redirected, deepening blood shortages across the region. Qilin, which surfaced in 2022 as a Ransomware-as-a-Service (RaaS) operation, claimed responsibility and dumped the stolen data on its dark web leak site after Synnovis refused to pay.
Technically, the breach involved exfiltration of unstructured, fragmented data from Synnovis' systems. Reconstructing it took forensic experts and specialized platforms, which is a big part of why notifications dragged past the one-year mark. The exact initial access vector stays undisclosed, but I track this crew, and Qilin's history points to the usual front doors: phishing, exploited vulnerabilities, or compromised credentials. Once inside, the operators almost certainly moved laterally, encrypting systems and stealing data before naming a price. Synnovis, working with its NHS trusts, chose not to pay—an ethical stance that kept money out of criminal hands but stretched the recovery out painfully.
Why This One Cuts Deeper
Past the immediate chaos, Synnovis exposes a systemic problem in healthcare. Pathology data may need clinical expertise to interpret, but pieced together it still feeds identity theft, medical fraud, or targeted extortion. Patients weren't notified directly—that fell to the NHS organizations—so the breach chips away at trust in an already strained system. It fits a wider pattern, too: Qilin alone has hit over 300 victims, leaning on the high stakes of sensitive data and downtime.
The blast radius spread right through London's healthcare ecosystem and forced a hard look at third-party risk. As a partnership between SYNLAB and NHS trusts, Synnovis embodies how interconnected modern medical services have become, where one vendor compromise cascades into widespread disruption. In the UK, it fed discussion about tougher cyber laws, but it also exposed real gaps in proactive detection. Ransomware isn't only about encryption anymore. Data theft for double extortion adds a layer that makes post-breach investigation slow and expensive—the same double-extortion playbook I keep seeing pair lateral movement with data theft.
The Lesson: Catch Them in the Network, Not at the Ransom Note
Synnovis makes one thing plain. Perimeter defenses alone don't hold against a determined RaaS crew. Spotting lateral movement and exfiltration early could have blunted the damage, and that's exactly where deception earns its keep. Scatter honeytokens—fake but believable data like bogus patient records or credentials—across your network, and you've planted tripwires. The moment an attacker reads or exfiltrates one, the alert fires, giving your team room to respond before mass encryption or theft.
In a pathology database like Synnovis', salting honeytokens among the real entries would have flagged the unauthorized queries and exports. Fake credentials tucked into code repositories or logs lure attackers into outing themselves the instant they're used. Breach traps—decoy servers dressed up as production—pull intruders sideways and buy time to isolate and investigate. This is the core of what Mine2.io builds, with automated deployment and monitoring that doesn't disrupt live operations. It's also why deception keeps working when attackers bring EDR killers to the fight, and why we leaned on it to blunt the Stryker wiper.
You don't have to overhaul anything to get there; you layer intelligence into what you already run. In healthcare, where data integrity is everything, deception complements EDR by focusing on attacker behavior rather than known signatures. Synnovis reminds us that refusing the ransom is the right call, but catching the intrusion early is the better one. If you want to see how the tokens get seeded, the Mine2 product page lays it out—and when you're ready, book a demo and we'll map the tripwires to your environment.
Riya
Principal Threat Researcher, Mine2 Labs
Riya tracks active threat campaigns and APT tradecraft at Mine2 Labs, translating real-world attacker behaviour into practical detection ideas.
Recent Articles
Your EDR Is Dead — Now What? Why Deception Is the Detection Layer That Survives EDR Killers
Ransomware's Invisible Kill Chain: Why Lateral Movement Is the Phase Your EDR Can't See
81 Million Logins, One Skipped Checkbox: Inside the LSHIY ROPC Campaign (Pipeline Test)
Need Security Help?
Protect your organization with MINE2's cyber deception platform.
