Skip to content
CityAM
Main navigation
  • News
    • News
      • Latest Business News
      • Economics
      • Politics
      • Tech
      • Banking
      • FTSE 100 Live
      • Retail
      • Insurance
      • Legal
      • Property
      • Transport
      • Markets
    • From our partners
      • AON
      • Bayes Business School
      • Canada BIDs
      • Central London Alliance CIC
      • Destination City
      • Halkin
      • Olympia
      • Inside Saudi
      • Tottenham Hotspur Stadium
      • Santander X
      • YEAR SIX Dividend
    • Featured

      The next person to shop your store may not be a person at all

      AI shopping agents are rewriting the rules of online retail across North America

      Submit a story

      Tell us your story.

      Submit
  • Opinion
  • Sport
    • Latest Sports News
      • Sport
      • Sport Business
    • From our partners
      • The Morning Briefing: SBS x CityAM
      • Aramco Team Series
      • LIV Golf
    • Featured

      Cohere's Aidan Gomez bets the house on 'sovereign AI' with Aleph Alpha merger valuing the group at $20bn

      Cohere CEO Aidan Gomez on stage discussing the Toronto AI lab's strategy

      Submit a story

      Tell us your story.

      Submit
  • Life&Style
    • Life&Style
      • Life&Style
      • Toast the City Awards
      • The Magazine
      • Travel
      • Culture
      • Motoring
      • Wellness
      • The RED BULLETiN
      • Do it with Shared Ownership
      • Media Speak Hub
    • Featured

      Moonvalley's Naeem Talukdar is selling Hollywood the one thing rival AI video tools cannot: legal cover

      Moonvalley's Marey AI video model produces Hollywood-grade footage trained on licensed data

      Submit a story

      Tell us your story.

      Submit
  • Investec
  • Events
  • Latest Paper
Wednesday 28 May 2025 3:31 pm

NHS patient data at risk in major cyber attack

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
AI and security
AI security

A newly uncovered cyber attack has exposed sensitive information at two major NHS trusts, raising fears that patient records could be at risk.

Experts have warned that the hack, linked to a vulnerability in widely used mobile management software, marks a growing threat to critical UK infrastructure.

University College London hospitals, NHS Foundation Trust, and University Hospital Southampton, NHS Foundation Trust were among the victims identified in a widespread cyber breach analysed by cybersecurity firm EclecticIQ.

The company have said hackers exploited a security flaw in Ivanti Endpoint Manager Mobile, or EPMM, which manages work phones to gain clandestine access to trusted systems.

Cyber attack exploits vulnerability

Unlike the recent wave of cyber attacks on British retail, the breach appears to have involved the quiet extraction of data through a remote code execution vulnerability.

The flaw was discovered on May 15th and has since been patched by Ivanti; however, experts have warned that systems already compromised may still be vulnerable.

Cody Barrow, chief executive of EclecticIQ an former US cyber command adviser, told Sky News the hack presents an “urgent wake up call” for the NHS.

“The potential compromise scope goes well beyond data theft. We’re looking at the risk of unauthorised access to highly sensitive patient records, disrupted appointments, and even interference with critical medical devices”, he said.

Read more

NHS gives Palantir wider access to patient data amid growing backlash

NHS healthcare professionals in a hospital setting discussing patient care plans, wearing uniforms and medical equipment v...

According to EclecticIQ, affected data includes staff phone numbers, as well as authentication tokens – details which could be used to access deeper into trust networks.

The attackers have not been formally identified, but the firm said the use of an IP address in China and the tactics performed suggest links to previous China-based cyber actors.

NHS England investigates

NHS England confirmed it is investigating the incident with the National Cyber Security Centre (NCSC) and said its high-severity alert system had been activated to support trusts in affected systems.

“We provide 24/7 cyber monitoring and response across the NHS”, a spokesperson said.

The breach is the latest in a seemingly unstoppable string of cyber incidents targeting UK firms.

In the last couple of months, big, household names like Co-op, M&S, Harrods and – only yesterday – Adidas, have confirmed breaches on their systems.

Experts say the string of breaches highlights a widening threat landscape across the nation, with healthcare now firmly in the crosshairs.

Read more

Fifa World Cup under major threat of cyber terrorism

GettyImages 158774123 showcases a relevant business meeting scene, highlighting diverse professionals engaged in discussion.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech
  • Business

People & Organisations

  • cyber attack
  • cyber security
  • data breach
  • NHS
  • nhs trust
  • patient data
  • uk business

Trending Articles

  • KPMG’s Summer Friday half-day rollback signals deeper woes for Big Four giants

  • Inflation expectations at record high in interest rates signal

  • London Tech Week sums up everything wrong with UK tech

  • UK economy falters as deeper damage to growth to come

  • KPMG report on AI found riddled with AI hallucinations

More from CityAM

  • ZayZoon, the Calgary fintech born on a fishing boat, posts 1,487% growth as earned wage access goes mainstream

    ZayZoon co-founder Tate Hackert built the Calgary fintech around earned wage access
  • Fifa World Cup under major threat of cyber terrorism

    Sport Business
    GettyImages 158774123 showcases a relevant business meeting scene, highlighting diverse professionals engaged in discussion.
  • Botpress raises $25m as Quebec's Sylvain Perron pitches his startup as the 'infrastructure layer' for AI agents

    Botpress product UI: the Quebec startup pitches itself as the infrastructure layer for enterprise AI agents
  • FluidAI wins US FDA clearance for its surgical monitor as Waterloo's Youssef Helwa targets 100,000 operations

    FluidAI's Origin surgical monitor wins FDA clearance for use in US hospitals
  • The Debate: Should CEOs be held personally accountable for cyberattacks?

    Opinion
    Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.
  • UK ministers tell UK businesses to ‘step up’ cyber defences

    Tech
    The ICO said it initially planned to fine Capita a total of £45m, but this was later reduced by “mitigating factors”
  • Gambit Cyber Launches Vizier AI – An Autonomous Security Intelligence Workspace for Continuous Exposure Management

    Business Wire
  • M&S eyes up Brits’ weekly shops as food arm set to expand

    Retail
    News article image related to a general topic, possibly showcasing a relevant scene or event for a business website.
  • Terms & Conditions
  • Privacy Policy
  • Cookie Policy
  • News
  • Markets & Economics
  • Politics
  • Opinion
  • Life&Style
  • Personal Finance

Follow us for breaking news and latest updates

  • Facebook
  • X
  • Instagram
  • LinkedIn
Copyright 2026 CityAM Limited