NHS Lanarkshire hit by ransomware cyber-attack

NHS trust was also a victim of WannaCry ransomware

Hospital IT

NHS Lanarkshire was hit by a ransomware attack last Friday which caused appointments and procedures to be cancelled.

The health board confirmed that the malware is a new version of Bitpaymer, but it's unclear how it infiltrated NHS Lanarkshire's network.

NHS Lanarkshire has a number of hospitals including Wishaw General, Hairmyres and Monklands. On Saturday, it published a statement on Facebook saying that the staffing system and telephone were offline and unavailable.

A spokesperson told IT Pro that since it was a new malware variant the latest security software was unable to detect it. Following analysis of the malware, it can now be detected and blocked by the health board.

Advertisement - Article continues below

The spokesperson added that staff had worked through the weekend to reinstate IT systems.

Chief executive Calum Campbell said: "We quickly identified the source of the malware and investigations are ongoing as to how this was able to infiltrate our network."

"Our staff have worked hard to minimise the impact on patients and our contingency plans have ensured we have been able to continue to deliver services while the IT issues were resolved," Campbell added. "A small number of systems were affected with the majority restored over the weekend and the remainder on Monday."

Campbell added that NHS Lanarkshire was working to reschedule appointments. 

In May, NHS Lanarkshire was one of almost 50 NHS Trust's affected by WannaCry, a ransomware attack which encrypted computers and left many unusable in different areas of the health service. The attack affected over 200,000 computers in 150 countries and demanded $300 to $600 for users to access their files. At the start of August, the attackers emptied their $140,000 Bitcoin wallets who were hoping to get hold of the money and hide their trail.

Marcus Hutchins, the British citizen who stopped the spread of WannaCry, was arrested in Las Vegas after being charged with creating and distributing a banking Trojan called Kronos. Hutchins has been free on bail since 5 August but is unable to leave the US and has been placed under electronic surveillance.

Featured Resources

The essential guide to cloud-based backup and disaster recovery

Support business continuity by building a holistic emergency plan

Download now

Trends in modern data protection

A comprehensive view of the data protection landscape

Download now

How do vulnerabilities get into software?

90% of security incidents result from exploits against defects in software

Download now

Delivering the future of work - now

The CIO’s guide to building the unified digital workspace for today’s hybrid and multi-cloud strategies.

Download now



Hackers abuse LinkedIn DMs to plant malware

25 Feb 2019

Best antivirus for Windows 10

3 Sep 2019

Best free malware removal tools 2019

8 Mar 2019

Most Popular

Microsoft Azure

Microsoft, not Amazon, is going to win the cloud wars

30 Nov 2019
Amazon Web Services (AWS)

What to expect from AWS Re:Invent 2019

29 Nov 2019

Raspberry Pi 4 owners complain of broken Wi-Fi when using HDMI

29 Nov 2019
Google Android

Samsung Galaxy A90 5G review: Simply the best value 5G phone

22 Nov 2019