Ransomware attack continues to disrupt healthcare in London nearly two years later

2026-04-18T02:51:54Z3417d22862ddc541feb783de5b4cac9eccf562601b05863f1ef74f4b28823c82
APT28DDoSDDoS-for-hireDOJEuropolFISANHSNorth KoreaPowerOFFRCERoundcubeSouth East LondonU.S. CongressUkrainecybercrimedata backloghealthcare disruptionlaptop farmslaw enforcementransomwareremote code executionsentencingsurveillancewebmail

What happened

Multiple security incidents and law-enforcement actions reported: an 18+ month-old ransomware attack continues to disrupt care at South East London NHS hospitals with systems not fully restored and large backlogs of delayed test results; a coordinated international takedown (more than 20 countries) led to four arrests in the crackdown on ‘PowerOFF’ DDoS-for-hire services; Ukraine attributes a suspected APT28 campaign to exploitation of vulnerabilities in the open-source Roundcube webmail platform that enable remote code execution when a user opens an email; the U.S. House passed a 10-day stop‑

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
therecord_media
Record identifier
3417d22862ddc541feb783de5b4cac9eccf562601b05863f1ef74f4b28823c82
Enrichment time
2026-04-18T02:51:54Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.