Qilin apologises to NHS victims for attack but demands $50 million ransom anyway

As the fallout from the ransomware attack against Synnovis, which provides pathology services to a group of London NHS hospitals, on 3 June continues, the cybercriminals behind the chaos claim to be sorry for the harm to patients caused. Not sorry enough to provide decryption keys or withdraw the $50 million ransom it has demanded, of course.

Synnovis says it is continuing the delivery of a recovery plan โ€œwhich prioritises both clinical criticality and the safe and secure restoration of servicesโ€. Meanwhile, its capacity to process samples has been โ€œsignificantly reducedโ€ and non-urgent results processing is being diverted to other pathology labs.

Qilin says sorry to NHS victims

The attack has been attributed to a ransomware group called Qilin. Threat intelligence specialists SOCRadar says that โ€œQilin ransomware is a sophisticated cyber threat group that has emerged as a significant player in the ransomware landscapeโ€ and is believed to be of Russian origin.

โ€œThis ransomware is distinguished by its advanced techniques, cross-platform capabilities, and targeted attacks, making it a formidable adversary for organisations worldwide,โ€ SOCRadar concludes.

As if attacking healthcare targets werenโ€™t heinous enough, the scumbags (there is no more polite description) behind the ransomware chaos have told the BBC that they are sorry to have caused a critical incident in which more than a thousand operations have had to be cancelled and patients left to suffer.ย 

The BBC World Service cyber correspondent, Joe Tidy, says a spokesperson for the gang spoke to the BBC by way of an encrypted chat. I hope you are sitting down as the sheer audacity on display is mind-boggling.

โ€œWe are very sorry for the people who were suffered because of it,” said the spokesperson. “Herewith we donโ€™t consider ourselves guilty and we ask you donโ€™t blame us in this situation.โ€

Blaming the UK government for the attack, apparently as a result of Russian citizens dying from a lack of blood supplies as part of the Ukraine conflict, it appears to be trying to turn this into a political protest rather than the financially motivated crime it most certainly is.

Read next: ChatGPT plays doctor: what happened when a real NHS doctor asked the AI for medical advice

How Synnovis is fighting back

โ€œWe take cybersecurity very seriously at Synnovis and have invested heavily in ensuring our IT arrangements are as safe as they possibly can be,โ€ said Mark Dollar, Synnovis CEO.

โ€œThis is a harsh reminder that this sort of attack can happen to anyone at any time and that, dispiritingly, the individuals behind it have no scruples about who their actions might affect.โ€

Of the $50 million ransom itself, Kevin Robertson, COO of Acumen Cyber, said such a huge sum โ€œclearly shows the attackers understand the chaos they are causing to Synnovis and hospitals across London.โ€

Indeed, and the reason that the hospitals were not directly targeted is likely that they knew no ransom would be paid by the UK government, hence going after the supply chain.

โ€œThe damage has been on a scale rarely witnessed after a cyber attack,โ€ Robertson continued. โ€œThese attacks are not going to go away, they are only going to increase, especially while Russia provides a safe haven for adversaries where they are celebrated for attacks, rather than penalised.โ€

And in case you were wondering who, exactly, Synnovis is, allow to me explain. It’s a pathology partnership between the London-based Guyโ€™s and St Thomasโ€™ NHS Foundation Trust, Kingโ€™s College Hospitals NHS Trust and SYNLAB, which claims to be Europe’s leading provider of laboratory diagnostic services.

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.