Software provider fined £3m over ransomware attack that hit NHS services

27 March 2025, 00:04

A woman’s hand pressing keys of a laptop keyboard
Cyber Monitoring Centre. Picture: PA

The Information Commissioner’s Office said Advanced Computer Software Group had been fined over security failings that put personal data at risk.

The UK’s data protection watchdog has fined a software provider £3 million over a 2022 ransomware incident which disrupted some NHS services.

The Information Commissioner’s Office (ICO) said Advanced Computer Software Group had been fined over security failings that put the personal information of 79,404 people at risk.

The firm provides IT and software services to organisations around the country, including the NHS and other health providers, handling information as part of its role as a data processor.

The incident, in August 2022, saw hackers access some systems of Advanced’s health and care subsidiary using a customer account that did not have multi-factor authentication (MFA) in place, with the attack leading to the disruption of critical services including NHS 111, and left some healthcare staff unable to access patient records.

The ICO’s investigation into the incident found that personal information belonging to 79,404 people was taken, including details of how to gain entry into the homes of 890 people who were receiving care at home.

The regulator concluded that the impacted Advanced subsidiary did not have the appropriate security measures in place prior to the incident.

Information Commissioner John Edwards said: “The security measures of Advanced’s subsidiary fell seriously short of what we would expect from an organisation processing such a large volume of sensitive information.

“While Advanced had installed multi-factor authentication across many of its systems, the lack of complete coverage meant hackers could gain access, putting thousands of people’s sensitive personal information at risk.

“People should never have to think twice about whether their medical records are in safe hands.

“To use services with confidence, they must be able to trust that every organisation coming into contact with their personal information – whether that’s using it, sharing it or storing it on behalf of others – is meeting its legal obligations to protect it.

“With cyber incidents increasing across all sectors, my decision today is a stark reminder that organisations risk becoming the next target without robust security measures in place.

“I urge all organisations to ensure that every external connection is secured with MFA today to protect the public and their personal information - there is no excuse for leaving any part of your system vulnerable.”

Last year, the ICO had announced its provisional intention to fine Advanced just over £6 million, but said the final reduction in the fine had occurred because of Advanced’s proactive engagement with the National Cyber Security Centre (NCSC), the National Crime Agency (NCA) and the NHS in the wake of the attack.

By Press Association

More Technology News

See more More Technology News

A Marks and Spencer store on Oxford Street in London

M&S pauses all online orders after cyber attack

Five iPhones in a row

Apple to move production of US iPhones from China to India over tariffs – report

LG Electronics livery at a trade fair

UK firm Nanoco sues LG over claims of TV technology patent infringement

A young girl in the dark staring into her mobile phone

Ofcom sets out new rules to force tech firms to protect children online

Hands on a laptop

Apple and Meta fined a combined £600m for breaching EU competition rules

Experiments with dimming the sun are set to go ahead

Experiments to dim the sun set to be approved within weeks

Hands using computer with artificial intelligence app

UK risks missing out on £200bn boost from slow take-up of AI, warns Google

A view of a webpage on a laptop, with several large knives for sale

Tech firms and bosses face large fines for failing to remove knife crime content

The hand of a young child using a laptop

New online safety rules will force tech firms to change, Ofcom insists

Undated handout photo issued by the Ministry of Defence of the Malloy Drone

UK restricts export of video game controllers to Russia amid use to pilot drones

A child using a laptop

Q&A: What do Ofcom’s new child online safety rules mean for social media?

Cabinet meeting

Social media curfews could be imposed on children, says Technology Secretary

A blurred woman using a mobile phone

UK to ban ‘sim farms’ used by scammers to send mass fraud messages

Apple and Meta have been fined a combined £600m for breaching EU competition rules

Apple and Meta fined a combined £600m for breaching EU competition rules

WhatsApp

WhatsApp launches privacy tool to stop users taking content off the platform

Intel logo

Intel planning to cut more than 20% of staff – reports