Synnovis / NHS (London hospitals) security incident

Synnovis was hit by a ransomware attack on June 3, 2024. The attack sharply reduced pathology testing capacity in south-east London and forced hospitals to postpone operations and outpatient appointments.

Last modified

Summary

  • Environment: Pathology lab services / NHS (UK)
  • Operational impact: The attack sharply reduced pathology testing capacity in south-east London and forced hospitals to postpone operations and outpatient appointments.
  • Financial impact: No financial figure is established by the reviewed source evidence
  • Record status: Developing record. Reviewed September 19, 2026; updated as evidence emerges.

What happened

In 2024, Synnovis experienced an incident in its pathology lab services / nhs (uk) environment. The retained source describes the attack path as follows: Synnovis was hit by a ransomware attack on June 3, 2024. [1]

The documented consequence was: The attack sharply reduced pathology testing capacity in south-east London and forced hospitals to postpone operations and outpatient appointments. [1]

Impact

  • Documented impact: The attack sharply reduced pathology testing capacity in south-east London and forced hospitals to postpone operations and outpatient appointments. [1]
  • No financial loss, ransom amount, recovery cost, or regulatory penalty is established by the reviewed source evidence.

Timeline

  1. Documented public update

    The Synnovis cyber incident – public questions and answers records the incident facts used in this briefing.

    [1]
  2. Briefing updated

    This briefing was last reviewed and updated on September 19, 2026.

Threat Group & Attack Vector

The retained source describes the attack path as follows: Synnovis was hit by a ransomware attack on June 3, 2024. The canonical record does not add intrusion steps beyond those supported by the source. [1]

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

Response

NHS England coordinated mutual aid, rerouted tests, and worked with Synnovis while laboratory systems were rebuilt. [1]

This account is bounded to Synnovis cyber incident – public questions and answers. Details absent from that evidence are left unresolved rather than inferred. [1]