Barts Health NHS Reveals Data Breach Linked to Oracle Zero-Day Exploited by Clop Ransomware
Barts Health NHS Trust has disclosed a significant data breach affecting patient and staff information following the exploitation of a critical vulnerability in Oracle E-Business Suite software by a ransomware group. The breach involves the theft of…
Barts Health NHS Trust has disclosed a significant data breach affecting patient and staff information following the exploitation of a critical vulnerability in Oracle E-Business Suite software by a ransomware group. The breach involves the theft of files from an invoice database, subsequently published on the dark web.
The compromised database includes invoice-related information spanning multiple years. Affected individuals include paying patients who received private treatment and former staff members with outstanding debts. Nearly half of the exposed files contain supplier information already available in the public domain. Additionally, records of accounting services provided to Barking, Havering, and Redbridge University Hospitals NHS Trust since April 2024 were also compromised. The breach remained undetected until November, when the stolen files were posted on the dark web.
The stolen files primarily contain names and addresses of patients liable for treatment payments. Electronic patient records and clinical systems remain unaffected. Both Barts Health and the associated hospitals are collaborating to mitigate the impact on affected individuals.
The breach involves the theft of files from an invoice database, subsequently published on the dark web.
Barts Health is pursuing a High Court order to prevent further dissemination of the data. The stolen information remains on encrypted dark web platforms and has not appeared on the general internet. However, there are potential risks of exploitation through social engineering tactics.
Barts Health is working closely with NHS England, the National Cyber Security Centre, the Metropolitan Police, and the Information Commissioner's Office. The trust has reported the breach to all relevant regulatory authorities and assures that core IT infrastructure security remains intact. Individuals seeking information about compromised data should review invoices received after treatment and contact the data protection officer if necessary. Resources are available for guidance on protecting personal information from scams.
Barts Health has apologized for the incident and is implementing additional safeguards with suppliers to prevent future occurrences.
Based on reporting by GBHackers.
