Personal patient and staff information has been posted on the dark web after hackers exploited a software vulnerability at Barts Health NHS Trust.
The criminal group, known as Cl0p, stole files from the trust’s database in August 2025, including names, addresses, and invoices of patients and staff who had paid for treatment or services over several years.
It also included files relating to accounting services provided since April 2024 to Barking, Havering and Redbridge University Hospitals NHS Trust.
In a statement, Barts Health said that its electronic patient record and clinical systems have not been affected by the attack and it is “confident” that its core IT infrastructure is secure.
Source: Digital Health, 9 December 2025
Recommended Comments
Create an account or sign in to comment