A large volume of data stolen during a cyber attack on a health board has been published by a ransomware group.
Cyber criminals were able to access a significant amount of data including patient and staff-identifiable information during the attack on NHS Dumfries and Galloway which began at the end of February.
Data relating to a small number of patients was released in March, and the hackers had threatened that more would follow.
The health board said that data accessed by the cyber criminals has now been published onto the dark web.
We should not be surprised at this outcome, as this is in line with the way these criminal groups operate
Julie White, NHS Dumfries and Galloway
It has set up a helpline for anyone concerned about the attack and is working with police and other agencies as investigations continue.
NHS Dumfries and Galloway chief executive Julie White said: “This is an utterly abhorrent criminal act by cyber criminals who had threatened to release more data.
“We should not be surprised at this outcome, as this is in line with the way these criminal groups operate.
“Work is beginning to take place with partner agencies to assess the data which has been published.
“This very much remains a live criminal matter, and we are continuing to work with national agencies including Police Scotland, the National Cyber Security Centre and the Scottish Government.
“NHS Dumfries and Galloway is conscious that this may cause increased anxiety and concern for patients and staff, with a telephone helpline sharing the information hosted at our website available from tomorrow.
“Data accessed by the cyber criminals has now been published onto the dark web – which is not readily accessible to most people.
“Recognising that this is a live criminal matter, we continue to follow the very clear guidance being provided to us by national law enforcement agencies.”
South of Scotland MSP Colin Smyth described the release of data as a “worrying development”.
It is important the NHS try to do what they did when the initial data was released, that is contact the individuals affected
MSP Colin Smyth
The Labour MSP told BBC Radio Scotland’s Good Morning Scotland programme: “There is no doubt it will cause a great deal of anxiety for patients and staff of NHS Dumfries and Galloway.”
He added hackers had been able to access “a very substantial amount of data”, including contact details for both staff and patients.
Read More
Mr Smyth said: “It is important the NHS try to do what they did when the initial data was released, that is contact the individuals affected.
“But if they can’t do that because the data is so substantial it is very important the NHS make that clear at an early stage, and at the very least contact the most vulnerable people whose data may have been released onto the dark web.”
A dedicated telephone helpline is open to the public from May 7, operating Monday to Friday 9am to 6pm, and Saturday 9am to 1pm on 01387 216 777.
The health board urged everyone to be alert for any attempts to access their work and personal data, or for approaches by anyone claiming to be in possession of either their personal data or NHS data – whether this approach comes by email, telephone, social media or some other means.
In all instances, people are advised to take down details about the approach and contact Police Scotland by phoning 101.
Information is being regularly updated on the website www.nhsdg.co.uk/cyberattack.
It is important to note that the incident remains contained to NHS Dumfries and Galloway and there have been no further incidents across NHS Scotland as a whole
Scottish Government spokesperson
A Police Scotland spokesman said: “Police Scotland inquiries are continuing into a cyber attack on NHS Dumfries and Galloway.”
A Scottish Government spokesperson said: “The Scottish Government is aware of a further publication of data on the internet, linked to the recent cyber attack on NHS Dumfries and Galloway.
“It is important to note that the incident remains contained to NHS Dumfries and Galloway and there have been no further incidents across NHS Scotland as a whole.
“The Scottish Government is working with the health board, Police Scotland and other agencies including the National Crime Agency and National Cyber Security Centre to assess the level of this breach and the possible implications for individuals concerned.
“The Scottish Government is continuing to provide support to NHS Dumfries and Galloway as they deal with this ongoing situation. This remains an on-going police investigation.”