RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Incident

Incident / From the archive · 3 June 2024 event · prepared 16 September 2026

A pathology supplier's ransomware outage postponed NHS procedures

Synnovis and the ICO describe how a lab supplier's outage delayed care and strained London's blood supply.

Visual for this record: A pathology supplier's ransomware outage postponed NHS procedures
Visual published by medtechnews.uk, shown for identification of the record. Credit: medtechnews.uk · source page ↗ Rights: owner-review-pending.

What happened

Synnovis, a pathology partnership serving hospitals and general practices across south east London, states in its own ongoing incident update, current as retrieved 16 September 2026, that a ransomware attack from 3 June 2024 affected almost all of its IT systems and interrupted many of its pathology services. The company says data was taken in haste and in a random manner from its working drives, and that no data was taken from its primary laboratory databases. On 20 June 2024, according to Synnovis, the attackers published the stolen information; the company says it obtained a legal injunction to try to prevent further publication.

The disruption affected blood testing capacity across the affected hospitals for an extended period, leading to the postponement of some procedures and appointments and prompting appeals for blood donations to cover shortfalls created by the reduced testing capacity. The UK's Information Commissioner's Office confirmed on 21 June 2024 that it was making inquiries into the incident and directed people concerned about their data to its own guidance and to NHS England.

Confidence and limits

Synnovis's own account is the primary source for what happened to its systems and data, corroborated by the ICO's confirmation that a data protection inquiry was underway; this gives official-corroboration standing rather than independent forensic confirmation. Synnovis states that identifying every organization whose data was affected took over a year given the scale and complexity of the stolen data, so this article does not attempt to state a final patient count. No ransomware group is named in the documents reviewed here, and this article does not speculate about attribution beyond what Synnovis and the ICO have stated.

Why it mattered

Pathology testing, including blood typing and cross-matching, sits upstream of many time-sensitive clinical decisions, so an outage at a single outsourced laboratory partner became a direct constraint on hospital capacity rather than a back-office inconvenience. The incident illustrates that clinical dependency chains extend beyond the hospital's own network to specialist suppliers whose availability is rarely tested the way a hospital's own systems might be, and that a ransomware attack on such a supplier can have consequences, like blood shortages, that look nothing like a typical data breach.

Defensive takeaway

Identify every outsourced clinical or laboratory dependency in your care pathway, ask the supplier what its ransomware recovery time objective is, and rehearse the manual fallback your own staff would need if that supplier's systems were unavailable for weeks rather than hours.

  • Which of our critical services depend on a single external laboratory, pathology or diagnostic supplier with no fallback?
  • Have we tested how long our clinical or business processes can run on manual or paper-based workarounds before quality or safety degrades?
  • Do our supplier contracts and due-diligence questions address ransomware recovery time specifically, not just general data protection compliance?

The Synnovis incident shows that a supplier's ransomware recovery timeline can become a hospital's own capacity constraint, which is a reason to treat critical outsourced clinical suppliers with the same continuity planning rigor as any in-house system.

Defensive takeaway

Map which clinical services in your organization depend on a single outsourced laboratory, pathology or diagnostic supplier, and confirm what your manual fallback procedure looks like if that supplier is unavailable for weeks.

Synnovis's own incident updates describe the technical sequence and the nature of the data taken, corroborated by the UK Information Commissioner's Office confirming it was making inquiries; the responsible ransomware group and the full patient count affected were still under investigation, which Synnovis says took over a year, so figures here are limited to what these two sources establish.

Sources & reading trail

Synnovis Cyber Update ↗

Synnovis's own account states the 3 June 2024 ransomware attack affected almost all its IT systems, that data was taken from working drives rather than primary lab databases, and that stolen data was published on 20 June 2024.

company-primary · Source published: Not established · Retrieved: 16 September 2026

ICO statement in response to Synnovis cyber attack ↗

Confirms the UK data protection regulator was making inquiries into the incident and directed affected individuals to NHS England and ICO guidance.

court-or-regulator-primary · Source published: 21 June 2024 · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.