Cybersecurity News Hub
No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us
No Result
View All Result
Cybersecurity News Hub
No Result
View All Result
Home Data Breach

NHS supplier hit with £3m fine for security failings that led to attack

Cyberinchief by Cyberinchief
December 6, 2025
Reading Time: 3 mins read
0
NHS supplier hit with £3m fine for security failings that led to attack



A Birmingham-based software provider has been handed a £3 million fine for security failings that led to a ransomware attack on the NHS.

The Information Commissioner’s Office (ICO) said Advanced Computer Software Group failed to use appropriate security measures before the 2022 attack, which put the personal information of tens of thousands of NHS patients at risk. 

Advanced provided the NHS with a range of patient management and health-related products, including Adastra, Caresys, Carenotes, Odyssey, Crosscare, Staffplan, and eFinancials.

RELATED POSTS

UK Hospital Asks Court to Stymie Ransomware Data Leak

These five countries recorded the most third-party data breaches last year

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

But there were gaps in its use of multi-factor authentication (MFA), a lack of comprehensive vulnerability scanning, and inadequate patch management, according to the data protection watchdog.

“The security measures of Advanced’s subsidiary fell seriously short of what we would expect from an organisation processing such a large volume of sensitive information,” said information commissioner John Edwards.

“While Advanced had installed multi-factor authentication across many of its systems, the lack of complete coverage meant hackers could gain access, putting thousands of people’s sensitive personal information at risk.”  

The hackers, believed to be the LockBit ransomware group, accessed certain systems of Advanced’s health and care subsidiary via a customer account that lacked MFA.

Sign up today and you will receive a free copy of our Future Focus 2025 report – the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives

Personal information belonging to 79,404 people was taken in the attack, including details of how to gain entry into the properties of 890 people who were receiving care at home.

Buy JNews
ADVERTISEMENT

Emergency prescription services, ambulance dispatching systems, and the non-emergency 111 phone line were affected, with some healthcare staff unable to access patient records.

“People should never have to think twice about whether their medical records are in safe hands,” said Edwards.

“To use services with confidence, they must be able to trust that every organisation coming into contact with their personal information – whether that’s using it, sharing it or storing it on behalf of others – is meeting its legal obligations to protect it.”

The fine forms part of a voluntary settlement. And while very large, it’s less than Advanced might have been facing – the ICO warned last summer in its provisional findings that it planned to hit the company with a £6.09 million penalty.

What’s changed since then is the company’s proactive engagement with the National Cyber Security Centre (NCSC), the National Crime Agency (NCA) and the NHS, and the steps it’s taken to mitigate the risk to those impacted by the attack. 

However, the ICO said the fine sends a salutary message to other organizations that may be a bit slapdash about the security of personal data.

“With cyber incidents increasing across all sectors, my decision today is a stark reminder that organisations risk becoming the next target without robust security measures in place,” said Edwards.

“I urge all organisations to ensure that every external connection is secured with MFA today to protect the public and their personal information - there is no excuse for leaving any part of your system vulnerable.” 

MORE FROM ITPRO



Source link

Tags: attackfailingsfineHitledNHSSecuritysupplier
ShareTweetPin
Cyberinchief

Cyberinchief

Related Posts

UK Hospital Asks Court to Stymie Ransomware Data Leak
Data Breach

UK Hospital Asks Court to Stymie Ransomware Data Leak

December 8, 2025
These five countries recorded the most third-party data breaches last year
Data Breach

These five countries recorded the most third-party data breaches last year

December 8, 2025
LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net
Data Breach

LockBit 5’s “new secure blog domain” infra leaked already – DataBreaches.Net

December 7, 2025
Rethinking the CIO-CISO Dynamic in the Age of AI
Data Breach

Rethinking the CIO-CISO Dynamic in the Age of AI

December 6, 2025
HHS Outlines AI Road Map Amid Major Department Overhaul
Data Breach

HHS Outlines AI Road Map Amid Major Department Overhaul

December 5, 2025
Europcar data breach could affect up to 200,000 customers
Data Breach

Europcar data breach could affect up to 200,000 customers

December 4, 2025
Next Post
Top 5 Cybersecurity Skills That Will Get You Hired in 2026!

Top 5 Cybersecurity Skills That Will Get You Hired in 2026!

⚠️WhatsApp, Telegram नहीं चलेगा | WhatsApp & Telegram New Rule #whatsapp #telegram #cybercrime

⚠️WhatsApp, Telegram नहीं चलेगा | WhatsApp & Telegram New Rule #whatsapp #telegram #cybercrime

Recommended Stories

कभी हैक नहीं होगा अकाउंट! | WHATSAPP | GMAIL | Amit Dubey Cyber Crime Investigator | SKT PODCAST

कभी हैक नहीं होगा अकाउंट! | WHATSAPP | GMAIL | Amit Dubey Cyber Crime Investigator | SKT PODCAST

November 3, 2025
🔥 Cybersecurity vs. Ethical Hacking : Which One Are You? | Simplilearn #shorts

🔥 Cybersecurity vs. Ethical Hacking : Which One Are You? | Simplilearn #shorts

October 21, 2025
ব্যাংকে বসেই প্রতারণা! গ্রেফতার বন্ধন ব্যাঙ্কের ৫ আধিকারিক | Cyber Crime | Bandhan Bank

ব্যাংকে বসেই প্রতারণা! গ্রেফতার বন্ধন ব্যাঙ্কের ৫ আধিকারিক | Cyber Crime | Bandhan Bank

November 8, 2025

Popular Stories

  • Allianz Life – 1,115,061 breached accounts

    Allianz Life – 1,115,061 breached accounts

    0 shares
    Share 0 Tweet 0
  • Prosper – 17,605,276 breached accounts

    0 shares
    Share 0 Tweet 0
  • साइबर अपराध | Illegal Payment Gateway & Rented Bank Accounts | MAMTA CHOPRA

    0 shares
    Share 0 Tweet 0
  • Miljödata – 870,108 breached accounts

    0 shares
    Share 0 Tweet 0
  • Snowflake Data Breach Explained: Lessons and Protection Strategies

    0 shares
    Share 0 Tweet 0

Search

No Result
View All Result

Recent Posts

  • Top 5 Mobile App Security Threats Leaders Must Prepare for in 2026
  • Microsoft On Women In Cybersecurity At Black Hat Europe 2025 In London
  • Polisi kembali ungkap sindikat Cyber Crime kejahatan Internasional – iNews Malam 09/03

Categories

  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos

Newsletter

© 2025 All rights reserved by cyberinchief.com

No Result
View All Result
  • Home
  • Cyber Crime
  • Cyber Security
  • Data Breach
  • Mobile Security
  • Videos
  • Advertise
  • Privacy Policy
  • Contact Us

© 2025 All rights reserved by cyberinchief.com

Newsletter Signup

Subscribe to our weekly newsletter below and never miss the latest News.

Enter your email address

Thanks, I’m not interested