Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
healthcare-sector-threatransomware-group-operationunderground-data-leakoperational-disruption

Extortion Attack on NHS Dumfries and Galloway Exposed Children’s Health Records

Updated 1mo agoFirst seen May 25, 20265 sources

NHS Dumfries and Galloway disclosed a cyberattack that raised the risk of patient data exposure, and weeks later stolen records linked to the incident were published online as part of an extortion campaign. Reporting indicated that highly sensitive files involving children’s health information were among the leaked material, escalating the impact from service disruption to a serious confidentiality breach affecting vulnerable patients.

The incident fits a broader pattern of ransomware and extortion operations targeting healthcare providers, where attackers disrupt clinical systems and use stolen data to pressure victims. Similar attacks previously hit New Zealand’s Waikato District Health Board, where a ransomware intrusion crippled hospital IT, forced lengthy restoration from backups across hundreds of servers and thousands of workstations, and underscored that healthcare organizations remain high-value targets because outages and data theft can directly affect patient care.

Share:
Extortion Attack on NHS Dumfries and Galloway Exposed Children’s Health Records
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
May 6, 20242y ago

Stolen children's health records from NHS Dumfries and Galloway posted online

By early May, stolen children's health records linked to the NHS Dumfries and Galloway incident were posted online as part of an extortion attempt, showing the attack had escalated to public data exposure.

Mar 19, 20242y ago

NHS Dumfries and Galloway discloses cyberattack with patient data at risk

NHS Dumfries and Galloway in Scotland disclosed a cyberattack and warned that patient data could be at risk, bringing the incident into public view.

Jun 2, 20215y ago

Waikato DHB restores over half of affected servers

Waikato DHB said more than half of the servers impacted by the ransomware attack had been restored over the previous four days. The organization said it would not pay the ransom and expected radiology and laboratory services to return the following week.

May 25, 20215y ago

Waikato DHB attack described as New Zealand's biggest cyberattack

Reporting a week later characterized the Waikato DHB incident as the biggest cyberattack in New Zealand history, marking a public escalation in understanding of the scale and severity of the breach.

May 18, 20215y ago

Waikato DHB hit by ransomware attack disrupting hospital systems

Waikato District Health Board in New Zealand suffered a ransomware attack that crippled parts of its health IT environment, affecting several hundred servers, major network sites, and thousands of workstations across hospital services.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Extortion Attack on NHS Dumfries and Galloway Exposed Children’s Health Records | Mallory