Ransomware

Ransomware Part 2: Why hospitals and schools keep getting hit — and what happens when they do

Hospitals and schools are not random targets. Here is the cold logic behind why they keep getting hit — and what a ransomware attack looks like from the inside.

Robert Shone 5 min read
Ransomware Part 2: Why hospitals and schools keep getting hit — and what happens when they do

There is a question that reasonable people ask when they see another headline about a hospital being hit by ransomware. Why would anyone do that? What kind of criminal targets a cancer ward or a primary school?

The honest answer has two parts. The first is that ransomware criminals are running a business, and hospitals and schools happen to have characteristics that make them highly attractive business targets. The second is that most of them are a long way from the consequences — which does not make what happens any less serious, but it does explain why appeals to decency tend not to work.

This article is about why these sectors keep getting targeted, what the attacks actually look like from the inside, and what they cost in terms that go beyond money.


Why hospitals and schools specifically

The analysis is almost depressingly rational once you understand what attackers are looking for.

They cannot afford to wait. A hospital cannot operate without its patient records, its medication systems, its lab results, and its scheduling software. A school facing GCSE season cannot wait three weeks for IT to be rebuilt. The more urgently an organisation needs its systems back, the more likely it is to consider paying — and the higher the ransom it will tolerate. Attackers who have mapped a hospital's systems know exactly how dependent that hospital is on them before they strike.

Their IT defences are often stretched. NHS trusts, schools, and colleges are not technology companies. Their core mission is patient care or education. IT is infrastructure, funded as such, often managed by small teams under significant resource pressure. Legacy systems — software and hardware that is old, unsupported, and difficult to update — are common across the NHS in particular. Old systems have known vulnerabilities that have been publicly documented and that criminals use specifically because they know many organisations have not patched them.

They hold sensitive data that is valuable to leak. Patient records contain medical histories, addresses, family details, and financial information. School records contain children's data — names, addresses, medical notes, SEND information, parental contact details. The threat to publish this data is powerful precisely because the people whose data it is are vulnerable.

There are a lot of them. The UK has over twenty thousand schools. There are hundreds of NHS trusts and GP practices. The sheer number of targets means even a modest success rate generates significant revenue.


What it looks like from the inside

The Synnovis attack of June 2024 is the most thoroughly documented UK healthcare ransomware incident of recent years, and worth understanding in detail.

Synnovis is a pathology services provider — a company that processes blood tests and other laboratory samples for NHS hospitals in London, including King's College Hospital, Guy's and St Thomas', and a number of others. On 3 June 2024, the Qilin ransomware group encrypted Synnovis's systems.

What followed illustrates how a single attack on a single supplier can cascade through a healthcare system. Blood tests could not be processed. Transfusions were delayed. Operations that required cross-matching blood were postponed. In the weeks that followed, thousands of outpatient appointments and hundreds of operations were cancelled or rescheduled. More than 10,000 planned appointments were affected in the first week alone.

In June 2025 — a year after the attack — King's College Hospital NHS Trust confirmed in writing that the disruption had contributed to the death of a patient. This is one of the very rare occasions on which a direct causal link between a ransomware attack and a patient fatality has been formally acknowledged by a health institution. It is stated here as fact, not for effect.

Synnovis did not pay the ransom. Qilin subsequently published nearly 400 gigabytes of patient data.


Schools: the softer target

The pattern in education is slightly different in mechanism but similar in impact.

In 2024, more than eighty ransomware attacks on UK education and childcare providers were reported to the ICO. Several schools were forced to close temporarily. In Shropshire, eleven schools in an unnamed academy chain were affected by a single attack; pupils could not submit coursework for weeks. In West Lothian, Edinburgh, Chester, and Blackpool, further attacks disrupted operations for months.

Attackers frequently time school attacks for maximum disruption — exam periods, the start of term. The data stolen typically includes pupil names, addresses, medical notes, SEND information, and parental contact details. When this data is published — which groups like Vice Society have done repeatedly — it falls to parents to be told that their child's details are now somewhere on the internet.

The DfE's own research confirms that 60% of secondary schools and 91% of universities experienced a breach or attack in the past year. Cybersecurity is a board-level concern for most schools. The gap is between awareness and adequate resourcing.


The human cost that statistics don't capture

What the incident reports and statistics do not capture well is what this looks like to the people inside it.

A teacher who arrives on a Monday morning to find every computer locked and no way to access lesson plans, pupil records, or the register. A nurse who needs a patient's blood results and cannot get them. A school business manager fielding calls from panicking parents while the police and ICO and DfE all want their own reports. An IT manager who has been awake for thirty-six hours and is being asked when everything will be back to normal.

For most large organisations, recovering from a significant ransomware attack takes months. Systems have to be rebuilt from scratch. Data has to be verified. Every device that was connected to the network has to be assessed. The organisation operates at reduced capacity throughout — doing the job it exists to do while simultaneously dealing with the consequences of a crime that happened to it without its fault.


What does this mean for me?

As a parent: if your child's school suffers a ransomware attack, the school is legally required to notify you if your child's data may have been accessed. Take any such notification seriously — your child's data may include information about medical conditions or family circumstances that could be exploited.

As a patient: the Synnovis experience is a reminder that cyber security in healthcare affects patient outcomes in the most direct possible way. NHS England has significantly increased its cyber security investment and incident response capability since 2024. Progress is real, if slow.

As an employee or volunteer at any organisation: the entry point for most ransomware attacks is a human action — a clicked link, an opened attachment, a reused password. The security training your organisation offers is not box-ticking. It is directly relevant to whether your organisation becomes the next headline.

Next Tuesday: the impossible question — to pay or not to pay.


🧠 The Human Factor

Technology involved Ransomware targeting legacy NHS systems, school network infrastructure, and the supply chain connections between healthcare providers and their IT and pathology suppliers
Root cause Organisations that are mission-critical, resource-constrained, and reliant on complex legacy infrastructure make attractive targets — the dependency on their systems is precisely the lever attackers use
What was at risk Patient care and patient safety, pupils' sensitive data, and in the Synnovis case the life of at least one patient — confirmed by King's College Hospital NHS Trust in June 2025
Prevention Adequate IT resourcing; supply chain security checks; staff training on phishing; offline backups tested regularly

References and sources

  • Synnovis/Qilin attack and patient death confirmation — King's College Hospital NHS Trust, June 2025; The Register
  • NHS England ransomware response and investment — ncsc.gov.uk
  • DfE / Government Cyber Security Breaches Survey 2025/2026 — Education Annex
  • Shropshire school attack (11 schools) — Computing.co.uk, July 2025
  • ICO: 80+ ransomware attacks on UK education, 2024 — ico.org.uk