Recent Breaches
Breaches
2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen2026NHS ScotlandUndisclosed records stolen2026HertzUndisclosed records stolen2025Marks & Spencer9.4M records stolen2025PayPal35K records stolen2025Jaguar Land RoverUndisclosed records stolen2025Co-operative GroupUndisclosed records stolen2024National Public Data2.9B records stolen2024Ticketmaster560M records stolen2024Change Healthcare100M+ records stolen2024AT&T73M records stolen2024Dell Technologies49M records stolen2023Progress Software (MOVEit)77M+ records stolen202323andMe6.9M records stolen2023Royal MailOperations halted records stolen2023British LibraryUndisclosed records stolen2023MGM ResortsUndisclosed records stolen2022Uber57M records stolen2022LastPass33M records stolen2022Optus9.8M records stolen2022Medibank9.7M records stolen2022Twitter5.4M records stolen2026NHS ScotlandUndisclosed records stolen2026HertzUndisclosed records stolen2025Marks & Spencer9.4M records stolen2025PayPal35K records stolen2025Jaguar Land RoverUndisclosed records stolen2025Co-operative GroupUndisclosed records stolen2024National Public Data2.9B records stolen2024Ticketmaster560M records stolen2024Change Healthcare100M+ records stolen2024AT&T73M records stolen2024Dell Technologies49M records stolen2023Progress Software (MOVEit)77M+ records stolen202323andMe6.9M records stolen2023Royal MailOperations halted records stolen2023British LibraryUndisclosed records stolen2023MGM ResortsUndisclosed records stolen2022Uber57M records stolen2022LastPass33M records stolen2022Optus9.8M records stolen2022Medibank9.7M records stolen2022Twitter5.4M records stolen2026PowerSchool62.4M records stolen2026DISA Global Solutions3.3M records stolen2026Globe Life850K records stolen
View All →
Back to Knowledge Vault
News28 May 20253 min read

Two NHS Trusts Targeted via Ivanti Vulnerability

Two major NHS trusts— University College London Hospitals NHS Foundation Trust and University Hospital Southampton NHS Foundation Trust —have been exposed in a…

Mark Fermor

Mark Fermor

Director & Co-Founder, Firevault

Share
A hospital building exterior at blue hour with emergency lighting and visible infrastructure

Two major NHS trusts—University College London Hospitals NHS Foundation Trust and University Hospital Southampton NHS Foundation Trust—have been exposed in a newly identified cyberattack, after threat actors exploited a vulnerability in a widely used device management platform.

The breach, linked to Ivanti Endpoint Manager Mobile (EPMM), enabled attackers to gain unauthorised access to internal systems. Security analysts confirm that this was not a ransomware event, but a stealth intrusion designed to extract sensitive information without triggering standard alarms.

The software in question is commonly deployed across enterprise and public sector environments to manage and secure employee mobile devices. In this instance, attackers exploited a known flaw to infiltrate network environments and access data silently.

Cybersecurity experts warn that the incident could result in the exposure of highly sensitive patient records and operational data.

“This represents a clear example of the growing threat posed by software-based vulnerabilities, especially in systems that underpin large, distributed networks such as those used in healthcare,” one analyst stated. “The data wasn’t locked—it was taken, quietly.”

The breach forms part of a broader campaign affecting organisations in the UK, Europe, the US, and Asia, with victims spanning healthcare, government, and commercial sectors.

A Wake-Up Call for Healthcare Security

The attack highlights a shift in tactics from disruptive ransomware to clandestine data harvesting, where the goal is no longer to shut down systems but to extract valuable information unnoticed.

With investigations ongoing, NHS security teams and national cybersecurity authorities are assessing the scope of the breach and issuing guidance to mitigate further exposure.

There is currently no confirmation of the volume or type of data accessed, and both trusts have yet to issue formal public statements.

Exploring Offline Alternatives

As cyber threats grow increasingly sophisticated, some organisations are beginning to reconsider the default assumption that all data must remain connected. Solutions such as Firevault a fully offline digital vault are gaining attention for offering a fundamentally different approach: disconnecting critical files from the internet entirely.

By physically isolating sensitive digital assets, Firevault aims to render data invisible and inaccessible to remote attackers, regardless of how advanced their intrusion methods may be. In a climate where exploits can sit undetected for months, offline storage is becoming part of a wider conversation around resilience and patient data protection.

This latest breach reinforces the urgency for healthcare providers to not only patch software and strengthen monitoring, but also rethink their exposure surface and ask what truly needs to stay online.

About the author

Mark Fermor

Mark Fermor

Director & Co-Founder

The driving force behind Firevault's market presence, combining commercial vision with deep tech insight.

Share this article

News28 May 20253 min read

Two NHS Trusts Targeted via Ivanti Vulnerability

Two major NHS trusts— University College London Hospitals NHS Foundation Trust and University Hospital Southampton NHS Foundation Trust —have been exposed in a…

Two NHS Trusts Targeted via Ivanti Vulnerability
Mark Fermor
Published by Mark Fermor, Director & Co-Founder

    Your privacy matters

    We use cookies to keep the site running smoothly and to understand how you use it. You are in control. Privacy Charter · Cookie Policy