Document resource
Background Approximately 30% of UK charities reported experiencing a cyber security breach or attack in the past year (Department for Science, Innovation and Technology, Home Office. Cyber security breaches survey 2025. GOV.UK [internet]), and healthcare providers are increasingly targeted (Torjesen. BMJ 2024;385:q1389). Ransomware is a malicious software that encrypts data, holding it hostage until a ransom is paid.In October 2023, our hospice was the subject of a ransomware attack, all fileservers were encrypted, and data exfiltrated. The threat actors demanded £500,000, threatening to release our data on the dark web.Aim Minimising patient service disruption, identifying exfiltrated data, preventing public data breaches, tracing the infiltration point, and strengthening security to the highest level. Not to engage with the threat actors.Methods We disabled virtual network cards and identified the ransomware as ‘No Escape’. All Windows servers were infected, while Linux and Windows desktops remained unaffected. Infected servers were restored quickly to maintain essential care. Encrypted files were deleted, systems cleansed, and data restored from offline backups. We also engaged external forensic IT consultants to monitor the dark web for data leaks and assess our systems for further vulnerabilities. The Information Commissioner’s Office was informed as a regulatory requirement.Results The attackers exploited a missed security patch in Citrix NetScaler. In response, we’ve shifted to a co-managed IT model with automated server updates, migrated critical systems to secure cloud platforms, and deployed RMM software across all devices. We also transitioned to O365, using Microsoft Defender for monitoring and ring groups for structured Windows updates.Conclusions As a clinical organisation, we promote a learning culture. We have addressed the vulnerabilities that left us exposed and implemented robust mitigation. We felt passionately about sharing our experience and learning not only to encourage other hospices to review their cyber security practices, but also to serve as a source of support, should any other organisation fall victim to this crime – it can be an isolating experience.