NHS Dumfries and Galloway hit by focused and ongoing cyberattack

Organization
NHS Dumfries and Galloway
Exploit
Ransomware
Industry
Healthcare

NHS Dumfries and Galloway, the Scottish health board covering a region of about 150,000 people, announced on March 15, 2024 that it was the target of what it described as a focused and ongoing cyberattack. The board said there had been incursions into its systems and warned that services could be disrupted, although patient care was not immediately affected.

Officials said there was a risk that the attackers had acquired a significant quantity of data, potentially including information identifying patients and staff. The board worked with the Scottish Government, Police Scotland, the National Cyber Security Centre, the National Crime Agency and NHS National Services Scotland, and later confirmed that the Information Commissioner's Office had been informed. It said its main GP health records system had not been touched.

On March 19 chief executive Jeff Ace said systems were generally running as normal while the investigation continued. On March 27 a ransomware group calling itself INC Ransom published clinical information relating to a small number of patients as proof that it held the data.

The group went on to release roughly three terabytes of material in May 2024, after which the board advised everyone in the region to assume some of their data was likely to have been published online. A dedicated public helpline ran until August 2024, and in a 17 December 2025 update the board described re-establishing multi-agency IT links with partners and stakeholders and reviewing its records retention processes through the recovery phase.

Sources