Skip to content
LatestMike Ashley’s Frasers snaps up Harvey Nichols 
CityAM Canada

Canadian business, markets & economy · Friday, 14 August 2026

  • Business
  • Markets
  • Economy
  • Technology
  • Politics
  • Energy
  • Property
  • Opinion
Wednesday 28 May 2025 3:31 pm

NHS patient data at risk in major cyber attack

By: Saskia Koopman

Tech Reporter

Add as a preferred source on Google
AI and security
AI security

A newly uncovered cyber attack has exposed sensitive information at two major NHS trusts, raising fears that patient records could be at risk.

Experts have warned that the hack, linked to a vulnerability in widely used mobile management software, marks a growing threat to critical UK infrastructure.

University College London hospitals, NHS Foundation Trust, and University Hospital Southampton, NHS Foundation Trust were among the victims identified in a widespread cyber breach analysed by cybersecurity firm EclecticIQ.

The company have said hackers exploited a security flaw in Ivanti Endpoint Manager Mobile, or EPMM, which manages work phones to gain clandestine access to trusted systems.

Cyber attack exploits vulnerability

Unlike the recent wave of cyber attacks on British retail, the breach appears to have involved the quiet extraction of data through a remote code execution vulnerability.

The flaw was discovered on May 15th and has since been patched by Ivanti; however, experts have warned that systems already compromised may still be vulnerable.

Cody Barrow, chief executive of EclecticIQ an former US cyber command adviser, told Sky News the hack presents an “urgent wake up call” for the NHS.

“The potential compromise scope goes well beyond data theft. We’re looking at the risk of unauthorised access to highly sensitive patient records, disrupted appointments, and even interference with critical medical devices”, he said.

Read more

Champions Cup rugby team hacked in ransom attack with player data at risk

Rugby player in a pink uniform running with the ball, pursued by an opponent in a black jersey.

According to EclecticIQ, affected data includes staff phone numbers, as well as authentication tokens – details which could be used to access deeper into trust networks.

The attackers have not been formally identified, but the firm said the use of an IP address in China and the tactics performed suggest links to previous China-based cyber actors.

NHS England investigates

NHS England confirmed it is investigating the incident with the National Cyber Security Centre (NCSC) and said its high-severity alert system had been activated to support trusts in affected systems.

“We provide 24/7 cyber monitoring and response across the NHS”, a spokesperson said.

The breach is the latest in a seemingly unstoppable string of cyber incidents targeting UK firms.

In the last couple of months, big, household names like Co-op, M&S, Harrods and – only yesterday – Adidas, have confirmed breaches on their systems.

Experts say the string of breaches highlights a widening threat landscape across the nation, with healthcare now firmly in the crosshairs.

Read more

NHS data counters claims that £330m Palantir deal has led to ‘no improvement’

Brit are seeking financial support from the ‘Bank of Mum and Dad’ to afford private healthcare.

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Tech
  • Business

People & Organisations

  • cyber attack
  • cyber security
  • data breach
  • NHS
  • nhs trust
  • patient data
  • uk business

Trending Articles

  • Revolut takes flight with launch of new airport lounges

  • Grandparents fund university degrees to avoid inheritance tax net

  • Brompton Bicycle sues former adviser for ‘professional negligence’

  • Revolut chatbot goes rogue by charging users to cancel subscription

  • It’s not just Jason Arday, most of sociology is a scam

More from CityAM

  • Champions Cup rugby team hacked in ransom attack with player data at risk

    Sport Business
    Rugby player in a pink uniform running with the ball, pursued by an opponent in a black jersey.
  • NHS data counters claims that £330m Palantir deal has led to ‘no improvement’

    Tech
    Brit are seeking financial support from the ‘Bank of Mum and Dad’ to afford private healthcare.
  • Ignore Palantir’s political opponents and look at the data: this technology helps patients

    Opinion
    NHS logo on a white surface with visible water droplets, blue and white branding
  • Leeds NHS Innovation to Accelerate Global Adoption of AI-enabled Pathology for Cancer Diagnostics Through Epredia Partnership

    Business Wire
  • M&S to face shareholder grilling over cyber attack recovery

    Retail
    Marks and Spencer was one of three UK retailers to be targeted
  • New Victoria Hospital Goes Live with MEDITECH Expanse to Deliver New Era of Care

    Business Wire
  • London-listed healthcare services firm hit by cyberattack

    Markets
    Assura has been the subject of a ferocious bidding war for nearly six months
  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
CityAM Canada

Independent Canadian business, markets and economic journalism, published by CityAM Publishing in Toronto. Read our editorial standards and corrections policy.

CityAM Publishing, 3 Borden Street #301, Toronto, Ontario M5S 2M8, Canada.
Newsroom enquiries: contact the editorial desk.

Follow

LinkedInXRSSApple News

Sections

BusinessMarketsEconomyTechnologyPoliticsEnergyPropertyOpinion

Newsroom

About usEditorial standardsCorrectionsOur journalistsContact

Company

AdvertisePrivacy noticeTerms of useCookie preferences

© 2026 CityAM Publishing. All rights reserved.

PrivacyTermsCookiesContact

Nothing published on CityAM Canada constitutes investment advice or a recommendation to buy or sell any security. CityAM Canada is an independent Canadian edition and is not affiliated with any UK publication.