INC Ransom published data stolen from Alder Hey Children's NHS trust

Organization
UK - Alder Hey Children's NHS Foundation Trust
Exploit
Ransomware
Industry
Healthcare

On November 28, 2024, the INC Ransom extortion group posted on its leak site that it had taken patient records, donor reports and procurement data covering 2018 to 2024 from Alder Hey Children's NHS Foundation Trust in Liverpool. The group published a small sample, reported as eleven screenshots, containing what appeared to be full names and addresses of patients and donors, the amounts donors had given, medical reports with hospital numbers and dates of birth, and financial documents.

Alder Hey said it was aware that data had been published online and was working with the National Crime Agency and the Information Commissioner's Office to verify the material and assess the impact. Hospital services continued as normal and no appointments or procedures were cancelled.

In a December 5 update, the trust said a single attack on a shared digital gateway service had given the criminals unlawful access to data held by Alder Hey, Liverpool Heart and Chest Hospital NHS Foundation Trust and, to a limited extent, Royal Liverpool University Hospital. It added that, from its review of the published sample, it did not believe the data related to children and young people, and that a full forensic investigation was still under way. Affected individuals were to be contacted directly.

Infosecurity Magazine reported that an Alder Hey Citrix instance had stopped responding, raising the possibility that INC Ransom exploited the CitrixBleed vulnerability, a technique the group has used before.

Sources