Cyber Attack On NHS Software Services

British NHS 111 medical staff nationwide were left using pens and paper after a major cyber attack was carried out over the weekend. People seeking medical help via the service are being warned of delays due to a “major” computer system outage caused by the attack which affected the phone service and referrals to out-of-hours GPs.

The system was shut down by hackers thought to be linked to a hostile state and cyber crime experts have been drafted in to investigate.

Advanced, a firm providing digital services for NHS 111, said the attack was spotted at 07:00 on Thursday 4th August. The attack targeted the system used to refer patients for care, including ambulances being dispatched, out-of-hour appointment bookings and emergency prescriptions.

The British National Crime Agency said it was "aware of a cyber incident" and was working with Advanced. "A security issue was identified yesterday, which resulted in a loss of service. We can confirm that the incident is related to a cyber attack and as a precaution, we immediately isolated all our health and care environments. Early intervention from our Incident Response Team contained this issue to a small number of servers representing 2% of our Health & Care infrastructure." an Advanced spokesman said

Advanced suggested the issue might not be fully resolved until next week and family doctors in London were warned by NHS England they could see an increased number of patients sent to them by NHS 111 due to the severe technical issue. It said a letter to GPs in the capital stated the problem was affecting the electronic referral process for patients.

Officials believe the fallout will last until Tuesday at the earliest, with the public told there will be delays when ringing the hotline.

It’s feared disruption could drive patients to overstretched accident and emergency departments over the weekend. An NHS England spokesperson said there was currently minimal disruption, and it was monitoring the situation. "NHS 111 services are still available for patients who are unwell, but if it is an emergency please call 999," they said.  

  • The Isle of Wight NHS Trust declared a critical incident in response to ‘sustained pressure’ on its A&E services. 
  • The Welsh Ambulance Service warned it may take longer for calls to be answered over the weekend. It said: "There is a major outage of a computer system that is used to refer patients from NHS 111 Wales to out-of-hours GP providers.
  • A Scottish Government spokesperson said it was aware of reported disruption to one of NHS Scotland's IT suppliers' systems and is "working with all health boards collaboratively on a four nations basis with the National Cyber Security Centre and the supplier to fully understand potential impact".
  • A spokesperson for Northern Ireland's Department of Health said they are working to keep disruption to a minimum. "As a precaution, to avoid risk to other critical systems and services, access to the company's services from the HSC (Health and Social Care system) has been disabled, while the incident is contained," they said.

Commenting on the attack Ross Brewer of enterprise cyber security platform AttackIQ said, ‘’This latest breach bringing the NHS 111 service to its knees is yet another example of an IT supplier being used to gain access in order to bring down critical national infrastructure...  While the specific details in this case are still developing, typically compromises of suppliers are used as an entry point to gain access to the target organisation or the service a supplier may be running on their behalf."

Regardless of the entry point, organisations should have protection and detection mechanisms to stop such intrusions developing into a catastrophic service failure, according to Brewer.

"In the case of cloud services hosted by the third party suppliers, the provider should have similar protections. To often not enough testing of people, processes and technology is taking place to validate an organisation’s cyber security readiness." he added.

An NHS spokesperson said “There is currently minimal disruption, and the NHS will continue to monitor the situation as it works with Advanced to resolve their software system as quickly as possible, tried and tested contingency plans are in place for local areas who use this service.”    

 Pulse Today:     HSToday:     BBC:    Guardian:     Independent:     Metro:   STV:     LBC: 

You Might Also Read: 

Ireland’s Health Service Won't Pay Ransom:
 

« AI Driven Anomaly Detection In The Oil & Gas Industry
Taiwan's Government Websites Attacked Just Before Pelosi’s Visit »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

ManageEngine

ManageEngine

As the IT management division of Zoho Corporation, ManageEngine prioritizes flexible solutions that work for all businesses, regardless of size or budget.

Authentic8

Authentic8

Authentic8 transforms how organizations secure and control the use of the web with Silo, its patented cloud browser.

Security Compass

Security Compass

Security Compass, the Security by Design Company, enables organizations to shift left and build secure applications by design, integrated directly with existing DevSecOps tools and workflows.

Thales

Thales

Thales provides solutions, services and products that help its customers in the defence, aeronautics, space, transportation and digital identity and security markets to fulfil their critical missions.

HireVergence

HireVergence

HireVergence is a full service IT staffing and recruiting firm with a focus on cyber and information security.

Cyber Risk Opportunities

Cyber Risk Opportunities

Cyber Risk Opportunities was formed to enable middle-market executives to become more proficient cyber risk managers so their organizations can thrive.

InstaSafe Technologies

InstaSafe Technologies

InstaSafe®, a Software Defined Perimeter based (SDP) one-stop Secure Access Solution for On-Premise and Cloud Applications.

National Cyber Security Center (NCSC) - Hungary

National Cyber Security Center (NCSC) - Hungary

The National Cyber Security Center was established in 2015 by uniting the GovCERT-Hungary, National Electronic Information Security Authority (NEISA) and the Cyber Defence Management Authority (CDMA).

European Healthcare Fraud & Corruption Network (EHFCN)

European Healthcare Fraud & Corruption Network (EHFCN)

EHFCN is the only organisation dedicated to combating fraud, corruption and waste in the healthcare sector across Europe.

ISARR

ISARR

The ISARR software platform - your bespoke Risk, Resilience & Security Management solution. Simple, cost effective and adaptable, now and into the future.

Tyler Technologies

Tyler Technologies

Tyler Technologies is a leading provider of end-to-end information management solutions and services for local governments.

Naq Cyber

Naq Cyber

Naq is the number one platform for SMEs looking to become legally compliant and protect against cybercrime and other data-related incidents.

Elisity

Elisity

Elisity Cognitive Trust is a new security paradigm that combines Zero Trust Network Access and an AI-enabled Software Defined Perimeter.

Node4

Node4

Node4 provide advanced, cloud-led digital transformation solutions, delivered with technical expertise, innovation and exceptional service to drive your business forwards.

Delinea

Delinea

Delinea is a leading provider of cloud-ready privileged access management (PAM) solutions that empower cybersecurity for the modern, hybrid enterprise.

Technivorus Technology

Technivorus Technology

Technivorus is a deep-tech firm delivering customized Cybersecurity, Digital Marketing, Web & App Development, and multifarious IT services for businesses across the globe.

Safe Decision

Safe Decision

Safe Decision is an information technology company offering Cyber Security, Network, and Infrastructure Services and Solutions.

Sequentur

Sequentur

Sequentur is an award-winning Managed IT Services company. We are SOC 2 certified and provide Managed IT Services and Cybersecurity services to businesses nationwide.

Protega

Protega

Protega is a company specialized in Managed Cybersecurity Services (MSS) & SOC 24×7; management, risk & compliance (GRC); implementation of data protection technologies; and Red Team services.

GIS Consulting (GISPL)

GIS Consulting (GISPL)

From General Data Protection Regulations to advanced Network Infrastructure Audits, GIS Consulting has established a reputation as one the leading cyber security companies in the industry.