CVS Group took systems offline after unauthorised access to UK IT servers

Organization
CVS Group plc
Exploit
Hacking
Industry
Veterinary Services

CVS Group plc, one of the largest veterinary businesses in the United Kingdom, said on April 8, 2024 that it had detected and intercepted a cyber incident involving unauthorised external access to a limited number of its IT systems. The company took the affected systems offline as part of its response plan to prevent wider access.

CVS notified the relevant regulatory authorities, including the Information Commissioner's Office, because of the risk that personal information had been reached. It did not say whether the data related to clients, employees or both, and no group publicly claimed responsibility.

The group runs more than 500 practices across the UK, Australia, the Netherlands and Ireland and employs about 9,000 people. Only the UK operations were affected. Third-party hosted systems and the group's ecommerce platforms were not touched. Practices stayed open, but CVS said its containment response had caused considerable operational disruption over the past week, with phone systems affected and remaining systems running less efficiently under added security controls.

CVS engaged third-party specialists to investigate and said it expected disruption to continue for several weeks. It later reported exceptional costs of £4 million to £5 million from the incident and around £7 million of adverse revenue impact in its final quarter, and said the episode accelerated its migration to a cloud based practice management system. The company subsequently described the incident as fully resolved.

Sources