---
title: "Essex NHS hospitals: 2,380 patient records comp… | Firevault"
url: https://fire-vault.com/news/essex-nhs-hospitals-synnovis-breach-2380-records
description: "Mid and South Essex NHS Foundation Trust has confirmed around 2,380 patient test records were stolen via third-party diagnostics provider Synnovis, as the…"
lang: en-GB
---

News · Breach Analysis · 8 June 2026

# Essex NHS hospitals: 2,380 patient records compromised in Synnovis cyber attack

Mid and South Essex NHS Foundation Trust has confirmed around 2,380 patient test records were stolen via third-party diagnostics provider Synnovis, as the fallout from the June 2024 Qilin ransomware attack continues to widen.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

4 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fessex-nhs-hospitals-synnovis-breach-2380-records
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fessex-nhs-hospitals-synnovis-breach-2380-records&text=Essex%20NHS%20hospitals%3A%202%2C380%20patient%20records%20compromised%20in%20Synnovis%20cyber%20attack%0A%0AMid%20and%20South%20Essex%20NHS%20Foundation%20Trust%20has%20confirmed%20around%202%2C380%20patient%20test%20records%20were%20stolen%20via%20third-party%20diagnostics%20provider%20Synnovis%2C%20as%20the%20fallout%20from%20the%20June%202024%20Qilin%20ransomware%20attack%20continues%20to%20widen.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fessex-nhs-hospitals-synnovis-breach-2380-records

Image: Dimly lit empty NHS hospital corridor at dusk, illustrating the Mid and South Essex NHS Synnovis cyber attack (https://fire-vault.com/__l5e/assets-v1/bac2a0c6-f24b-4822-8b60-850efe68b119/news-essex-nhs-hospitals-synnovis-breach-2380-records-2x.jpg)

Dimly lit empty NHS hospital corridor at dusk, illustrating the Mid and South Essex NHS Synnovis cyber attack

Why it matters

## What this means for organisations holding critical data

Mid and South Essex NHS Foundation Trust (MSE) has confirmed that around **2,380 patient test records** were compromised in the cyber attack on diagnostics provider Synnovis, becoming the latest NHS organisation to surface in the long tail of the June 2024 Qilin ransomware incident.

## What happened

The trust, which runs Southend Hospital along with Basildon and Broomfield, and provides services at sites in Braintree, Maldon and Orsett, was notified of the breach in December 2025. The data sat with Synnovis, the third-party pathology provider, not on the trust’s own systems.

Dawn Scrafield, deputy chief executive for Mid and South Essex NHS Foundation Trust, said records relating to patients who had a mixture of specialist diagnostic tests were affected, and that some data is not directly linked to patients, so final numbers are still being confirmed. The trust said it will contact affected patients once they have been identified.

## What data was exposed

According to Synnovis, the stolen information could include:

- Names
- Dates of birth
- NHS numbers
- Postcodes
- Test results

Patients tested after 3 June 2024 are not believed to be affected. While the breached data did not come from the trust’s own systems, MSE has brought in external cyber security experts to support the response.

## The attack chain

Synnovis was hit by a ransomware attack (https://fire-vault.com/threats/ransomware) on **3 June 2024**, disrupting pathology services across multiple London and South East NHS organisations and significantly reducing its capacity to process tests. On **20 June 2024**, the attackers published stolen data files online. A Russia-linked cyber-criminal group known as **Qilin** previously claimed responsibility.

Eighteen months on, downstream trusts are still working out exactly which of their patients appear in the leaked files. MSE is one of several NHS organisations now confirming exposure as the review of the dumped data continues.

## Why this matters

This is, at heart, a supply chain breach. The trust did not lose control of its own infrastructure; it lost control through a service provider that aggregates sensitive data on its behalf. Pathology in particular concentrates highly identifying information, including NHS numbers and clinical results, in a small number of processing labs. When one of those labs is compromised, the impact lands across dozens of providers and millions of patients.

The harm is also long lived. Names, dates of birth and NHS numbers do not expire. Once they are in criminal hands they fuel identity fraud, targeted phishing and insurance abuse for years, regardless of how quickly the original incident is contained.

## Protection through physical disconnection

The Synnovis incident is a textbook case for keeping a copy of irreplaceable records on infrastructure that simply cannot be reached over the wire. Live diagnostic workflows have to be online. The historical archive does not.

Firevault stores sensitive records on a Layer 1 physically disconnected vault, governed by the VPPP framework (Vault, Policy, Permissions, Purpose) (https://fire-vault.com/vault/butterfly). The vault is only connected when an authorised action is taking place, and is otherwise unreachable by any remote attacker, including ransomware operators with valid credentials. A copy of patient records held this way would still exist, intact and uncopied, on the day a third-party processor is breached.

As Mark Fermor, Director and Co-co-founder of Firevault, has set out repeatedly: the lesson from incidents like Synnovis is not more layers of online defence, it is removing the most sensitive records from the attack surface altogether.

## Key takeaways

- **Supply chain is the perimeter.** An attack on a diagnostics processor became a breach for every trust that relied on it.
- **Patient PII has a long shelf life.** NHS numbers and dates of birth do not rotate; the harm window is measured in years.
- **Breach notification lags reality.** Patients are being identified eighteen months after the initial intrusion.
- **Online defence alone is not enough.** An archival copy held offline, on a physically disconnected vault, cannot be exfiltrated in the same event.
- **Third-party due diligence matters.** Where critical data is processed by a single provider, concentration risk needs to be priced in.

_Source: Braintree & Witham Times — Essex NHS hospitals records compromised in cyber attack (https://www.braintreeandwithamtimes.co.uk/news/26174950.essex-nhs-hospitals-records-compromised-cyber-attack)._

**How Firevault helps**

- **Offline Secure Storage (https://fire-vault.com/offline-secure-storage)** keeps gold-copy data physically disconnected from the network, so a ransomware or exfiltration event cannot reach it.
- **Control (https://fire-vault.com/control)** gives boards and operators a single view of what is online, what is isolated, and what is recoverable across the estate.
- **Firebreak (https://fire-vault.com/firebreak)** delivers hardware-enforced disconnection at Layer 1, so exposed credentials or compromised network paths cannot become a route into the vault.

_Talk to Firevault about Disconnect to Protect® (https://fire-vault.com/about) for your organisation._

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## Controls an auditor can physically verify

Firevault gives you physical separation, named custody and evidenced access, so compliance claims about isolation and control are things you can show, not just assert.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**Custody**Named, access-controlled hardware in a Firevault Bunker

**Evidence**Access windows and retrieval events are recorded

**Separation**Physical isolation that satisfies offline copy requirements

**Jurisdiction**Stored where your regulatory position requires

Related Reading

## You may also find these useful

Breach Analysis

### Dyfed-Powys Police confirms cyber attack as staff information may have been compromised

Dyfed-Powys Police has confirmed that a cyber attack identified on 14 September disrupted non-emergency systems and may have exposed staff information. The force says it has found no evidence that public data was accessed.

25 Sept 2026 3 min
https://fire-vault.com/news/dyfed-powys-police-cyber-attack-2026

Breach Analysis

### FBI investigates claims that hackers stole personnel and applicant data

The FBI is investigating unauthorised activity affecting its recruitment website after ShinyHunters claimed it stole sensitive records on current and former personnel and job applicants. The claimed scale remains unconfirmed.

22 Sept 2026 4 min
https://fire-vault.com/news/fbi-employee-applicant-data-breach-shinyhunters-2026

Breach Analysis

### Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later

Families of vulnerable children in Wiltshire, Bath and North East Somerset have been told their personal health information may have been accessed in a cyber attack on HCRG Care Group in February 2025, more than 18 months after the incident.

20 Sept 2026 4 min
https://fire-vault.com/news/hcrg-care-group-children-records-cyber-attack-2026

Breach Analysis

### FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

17 Sept 2026 4 min
https://fire-vault.com/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026

Breach Analysis

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min
https://fire-vault.com/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026

Breach Analysis

### CenterPoint Energy confirms hackers stole customer data through an exposed API

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

16 Sept 2026 4 min
https://fire-vault.com/news/centerpoint-energy-confirms-cyberattack-data-theft-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/essex-nhs-hospitals-synnovis-breach-2380-records#webpage",
    "url": "https://fire-vault.com/news/essex-nhs-hospitals-synnovis-breach-2380-records",
    "name": "Essex NHS hospitals: 2,380 patient records comp…",
    "description": "Mid and South Essex NHS Foundation Trust has confirmed around 2,380 patient test records were stolen via third-party diagnostics provider Synnovis, as the…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/__l5e/assets-v1/bac2a0c6-f24b-4822-8b60-850efe68b119/news-essex-nhs-hospitals-synnovis-breach-2380-records-2x.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/essex-nhs-hospitals-synnovis-breach-2380-records#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/essex-nhs-hospitals-synnovis-breach-2380-records#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Essex NHS hospitals: 2,380 patient records compromised in Synnovis cyber attack",
        "item": "https://fire-vault.com/news/essex-nhs-hospitals-synnovis-breach-2380-records"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "Essex NHS hospitals: 2,380 patient records compromised in Synnovis cyber attack",
    "description": "Mid and South Essex NHS Foundation Trust has confirmed around 2,380 patient test records were stolen via third-party diagnostics provider Synnovis, as the fallout from the June 2024 Qilin ransomware attack continues to widen.",
    "url": "https://fire-vault.com/news/essex-nhs-hospitals-synnovis-breach-2380-records",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/bac2a0c6-f24b-4822-8b60-850efe68b119/news-essex-nhs-hospitals-synnovis-breach-2380-records-2x.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/bac2a0c6-f24b-4822-8b60-850efe68b119/news-essex-nhs-hospitals-synnovis-breach-2380-records-2x.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/bac2a0c6-f24b-4822-8b60-850efe68b119/news-essex-nhs-hospitals-synnovis-breach-2380-records-2x.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/bac2a0c6-f24b-4822-8b60-850efe68b119/news-essex-nhs-hospitals-synnovis-breach-2380-records-2x.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-06-08T22:37:29.647228+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/essex-nhs-hospitals-synnovis-breach-2380-records"
    },
    "inLanguage": "en-GB",
    "articleSection": "Breach Analysis",
    "wordCount": 753,
    "keywords": "Essex, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "Mid and South Essex NHS Foundation Trust (MSE) has confirmed that around 2,380 patient test records were compromised in the cyber attack on diagnostics provider Synnovis, becoming the latest NHS organisation to surface in the long tail of the June 2024 Qilin ransomware incident. What happened The trust, which runs Southend Hospital along with Basildon and Broomfield, and provides services at sites",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  }
]
```