Hackers breach internal servers of tech provider for Britain’s health service
好的,我现在需要帮用户总结一篇文章的内容,控制在100字以内。首先,我得仔细阅读这篇文章,了解主要信息。 文章讲的是DXS International,一家英国科技公司,他们的软件在英国国家医疗服务体系(NHS)中被广泛应用。他们披露了一个网络安全事件,影响了内部系统。具体来说,他们在12月14日检测到未经授权的访问进入办公室服务器。公司已经控制了这次入侵,并且临床服务没有受到影响,一直在正常运行。 现在还不清楚NHS的患者数据是否被泄露,但公司已经通知了英国的数据保护监管机构ICO。NHS England的发言人还没有回应是否患者数据受到影响的问题。目前调查还在进行中,DXS正在与NHS的网络安全团队和外部专家合作。 此外,文章还提到这不是孤立事件,近年来针对英国健康科技供应商的攻击越来越多。例如去年Synnovis被勒索软件攻击导致至少一人死亡,还有2022年Advanced公司的攻击导致NHS 111服务中断。这些事件显示第三方系统的安全问题对医疗服务的影响。 最后,文章提到英国目前的网络安全法规并没有自动涵盖像DXS这样的第三方健康IT供应商。政府最近提出了新的《网络安全和弹性法案》,可能会对公司提出更高的安全要求。 总结一下,我需要把重点放在DXS公司的安全事件、影响范围、调查进展以及背景中的其他类似事件上。同时要控制在100字以内,并且不要使用特定的开头词。 现在组织语言:DXS International报告内部系统遭受网络攻击,未经授权访问办公室服务器于12月14日被发现。临床服务未受影响,但患者数据是否泄露尚不清楚。调查正在进行中,并已通知监管机构。此次事件凸显第三方健康IT供应商面临的网络安全风险。 </think> DXS International报告内部系统遭受网络攻击,未经授权访问办公室服务器于12月14日被发现。临床服务未受影响,但患者数据是否泄露尚不清楚。调查正在进行中,并已通知监管机构。此次事件凸显第三方健康IT供应商面临的网络安全风险。 2025-12-18 13:31:26 Author: therecord.media(查看原文) 阅读量:0 收藏

DXS International, a British technology company whose software is widely used throughout the National Health Service (NHS), has disclosed a cybersecurity incident affecting its internal systems.

In a notice to the London Stock Exchange, the company said it detected unauthorized access to office servers on December 14. DXS said it contained the breach and that its clinical services remained unaffected and operational throughout.

At present there is no confirmation whether NHS patient data was compromised, although the company said it has notified Britain’s data protection regulator, the Information Commissioner’s Office (ICO).

A spokesperson for NHS England did not immediately respond to a request for comment about whether patient data has been impacted.

DXS said investigations are ongoing and that it is working with NHS cybersecurity teams and external specialists “whose thorough investigations are underway to establish the nature and extent of the incident.”

The company, which added that it did not currently believe the incident would have a material adverse impact on its finances, provides clinical decision support and referral management tools used by GP practices and primary care networks across England.

Its products integrate with core NHS systems and, according to the company’s own statements, it supports around 10% of all NHS referrals in England, with its software touching the workflows for millions of registered patients.

The company is not a core electronic health record provider and does not hold central medical records, however patient data is processed by some of its systems used to provide clinical guidance to healthcare providers.

Not an isolated incident

The incident comes amid heightened concern over attacks on health technology suppliers in the United Kingdom that have underscored how incidents affecting third-party systems, even when not hosting core records, can have operational implications.

At least one patient is believed to have died following a ransomware attack on pathology provider Synnovis last year, with thousands of operations and appointments also cancelled.

Another ransomware attack impacting software supplier Advanced back in 2022 led to the temporary shutdown of the NHS 111 critical service used to triage non-emergency but urgent medical calls. 

In that incident, doctors, nurses and other staff were forced to resort to pen and paper to complete their jobs due to the impact on IT systems — provoking a crisis management COBR meeting in the British government as officials feared the impact the attack could have on patient care. Advanced was subsequently fined £3 million by the ICO for its security failings.

Britain's current regulations for cybersecurity do not automatically include third-party health IT suppliers like DXS within their provisions requiring them to meet specific security standards.

The government last month introduced its landmark Cyber Security and Resilience Bill to Parliament, threatening large fines for companies that fail to protect themselves from cyberattacks. Under the bill, companies that provide managed IT services to critical sectors, including healthcare, could be brought under the regulation.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Alexander Martin

Alexander Martin

is the UK Editor for Recorded Future News. He was previously a technology reporter for Sky News and is also a fellow at the European Cyber Conflict Research Initiative.


文章来源: https://therecord.media/uk-nhs-tech-provider-dxs-discloses-hack
如有侵权请联系:admin#unsafe.sh