In late June 2024 Qilin published material taken from Synnovis, reported at around 400GB, after a ransom demand was not met. Patient-identifiable information was among it, and reporting has put the number of NHS patients potentially affected near one million.
Put The Two 2024 Outcomes Side By Side
One paid and the data circulated anyway. One refused and the data was published. The suppression half of a ransom demand did not deliver in either case, which is a stronger statement than the corpus has previously been able to make.
The Decryption Half Is A Different Question
A decryptor either restores systems or it does not, and it can be tested on the day. That is a real thing to buy, and the corpus does not argue against buying it.
What these two cases sit against is the second half — the undertaking that the stolen copy will be destroyed. Nothing in either outcome suggests that undertaking is worth anything, and the file at 25-0215 records that it has no enforcement mechanism to begin with.
The Volume Figure Comes From The Group
Around 400GB, and near a million patients potentially affected, are figures originating with the attacker and with early reporting rather than with a completed review. Synnovis has since worked through its own forensic process.
This desk grades the file medium for that reason. That publication happened is established; how much and about how many is not.
Compiled from contemporaneous reporting, listed below. The 400GB volume and the near-one-million patient figure originate with the attacking group and with early reporting; both are labelled as claims and neither is treated as established. The comparison with Change Healthcare draws on 24-0301 and 24-0405 and is an argument about the mechanism, not a recommendation about whether to pay. Graded medium. Corrections: corrections@forensicpost.com.