A Major Ransomware Attack Has Hit NHS Systems Across England
Key takeaways
- A ransomware attack detected in late July 2026 disrupted NHS trusts across England, affecting patient records, scheduling, and communications
- Initial access was likely via phishing emails targeting NHS staff accounts, the most common ransomware entry vector
- A 2025 NHS England audit found roughly 22 percent of networked devices still running past end-of-support operating systems
- Healthcare was the most targeted sector for ransomware globally for the fifth consecutive year in 2025, with average recovery costs exceeding 10 million dollars per incident
The National Health Service has been targeted by ransomware before. The 2017 WannaCry attack is still the reference point for what a catastrophic cyber incident looks like in a healthcare setting, with roughly a third of NHS trusts in England affected and an estimated 19,000 appointments cancelled. Nearly a decade later, the threat has not gone away, and a new ransomware incident affecting NHS systems across England is a reminder of how persistently vulnerable critical healthcare infrastructure remains.
The attack, which was detected in late July 2026, disrupted digital systems at multiple NHS trusts. The specifics are still being confirmed by NHS England and the National Cyber Security Centre (NCSC), but early reports indicate that patient record access, appointment scheduling, and internal communications were affected at a number of sites. Some trusts reverted to paper-based processes while IT teams worked to contain the damage.
What we know so far
The ransomware variant used in this incident has not yet been publicly confirmed by authorities. Incident response teams from the NCSC and NHS Digital were deployed quickly, and the government's Cyber Security Operations Centre was activated. This faster institutional response reflects real progress since 2017, when the NHS had no central cyber incident team and response was chaotic.
Early indications suggest the initial access vector involved phishing emails targeting NHS staff accounts, which remains the single most common entry point for ransomware attacks against large organisations. Once inside, attackers likely moved laterally through NHS networks before deploying the ransomware payload across multiple systems simultaneously, the classic approach to maximising disruption before defenders can isolate affected systems.
As of the time of writing, no major patient data leak had been confirmed, though that assessment may change as forensic investigation continues. The attackers had reportedly made a ransom demand, which NHS England has so far declined to confirm or deny.
Why healthcare keeps getting hit
NHS trusts operate under chronic underfunding pressures that directly affect cybersecurity. Many trusts still run legacy systems, including older versions of Windows, that are no longer supported with security patches. Upgrading these systems requires both budget and downtime that resource-stretched hospitals struggle to find. The result is a structural vulnerability that no amount of staff training fully mitigates.
Healthcare organisations are also attractive targets for ransomware groups for a specific reason: the disruption of patient care creates pressure to pay quickly. A hospital cannot afford its systems to be down for weeks the way a retail company might tolerate. Attackers know this, which is why healthcare has consistently been among the most targeted sectors globally.
A 2025 report from the Ponemon Institute found that healthcare was the most targeted sector for ransomware for the fifth consecutive year, with average recovery costs exceeding 10 million dollars per incident when factoring in downtime, remediation, and reputational damage.
The funding gap
The UK government pledged 338 million pounds for NHS cybersecurity improvements between 2022 and 2025 as part of its national cyber strategy. Progress has been made, but the NHS's attack surface is enormous. There are over 200 trusts in England alone, each with its own IT infrastructure and varying levels of cybersecurity maturity.
The patching problem is the most tractable issue on paper but the hardest in practice. A 2025 NHS England audit found that roughly 22 percent of networked devices across NHS trusts were still running operating systems past their end-of-support date. Each one of those devices is a potential entry point.
What happens now
The immediate priority is restoring systems and confirming whether patient data was exfiltrated. If data was stolen, GDPR notification obligations kick in within 72 hours of confirmed knowledge, which means NHS trusts and NHS England may face regulatory scrutiny on top of the operational crisis.
Longer term, this incident will likely prompt another round of government commitments to NHS cybersecurity investment. Whether that investment translates into genuine security improvements or gets absorbed by the enormous backlog of basic IT maintenance the NHS already faces is the harder question. The pattern, incident followed by pledge followed by limited improvement followed by the next incident, has repeated too many times to be optimistic without specific structural changes.