Cyber Coercion in Healthcare: Evidence from the 2024 Synnovis Ransomware Attack
Abstract
This article examines the 2024 Synnovis ransomware attack on the United Kingdom’s National Health Service. The study employs a qualitative single-case design based on a structured desk review. The evidence was analysed through Borghard and Lonergan’s framework of cyber coercion. The findings show that Qilin clearly communicated a financial demand and imposed substantial operational, clinical, financial, reputational and informational costs through various disruption measures. However, these consequences demonstrate successful cost imposition rather than successful alteration of the target’s cost-benefit calculus. The ransom remained unpaid, indicating that the coercive pressure was insufficient to produce compliance. Qilin’s credibility was demonstrated through actual disruption and the publication of stolen data, while reassurance remained weak because payment could not guarantee system restoration, permanent data deletion, or protection from further exploitation. The article contributes to cyber-coercion research by extending its application to criminal ransomware and showing that coercive effectiveness depends partly on the relationship among service dependency, cost distribution, decision authority, and behavioural outcome.
References
Aash, P. (2025). Synnovis Data Breach. In FireCompass. https://firecompass.com/synnovis-data-breach/
Ahmed, S. K., Mohammed, R. A., Nashwan, A. J., Ibrahim, R. H., Abdalla, A. Q., Ameen, B. M. M., & Khidhir, R. M. (2025). Using Thematic Analysis in Qualitative Research. Journal of Medicine, Surgery, and Public Health, 6(6), 100198. https://doi.org/https://doi.org/10.1016/j.glmedi.2025.100198
Akyesilmen, N., & Akdag, Y. (2025). Norms, Institutions, and Challenges of Multilateral Cooperation. Insight Turkey, 27(2), 313–336. https://doi.org/10.2307/48829617
Alder, S. (2024). Ransomware Group Leaks Data from 300 Million Patient Interactions with NHS. In The HIPAA Journal. https://www.hipaajournal.com/care-disrupted-at-london-hospitals-due-to-ransomware-attack-on-pathology-vendor/
Aldosari, B. (2025). Cybersecurity in Healthcare: New Threat to Patient Safety. Cureus, 17(5). https://doi.org/10.7759/cureus.83614
Barbieri, M., Catania, G., Hayter, M., Aleo, G., Zanini, M., Sasso, L., & Bagnasco, A. (2025). Desk review as a methodological approach for identifying policies and gray literature: A case study. Nursing Outlook, 73(6), 102547. https://doi.org/10.1016/j.outlook.2025.102547
Bernard, R., Bowsher, G., & Sullivan, R. (2020). Cyber security and the unexplored threat to global health: a call for global norms. Global Security: Health, Science and Policy, 5(1), 134–141. https://doi.org/10.1080/23779497.2020.1865182
Borghard, E. D., & Lonergan, S. W. (2017). The Logic of Coercion in Cyberspace. Security Studies, 26(3), 452–481. https://doi.org/10.1080/09636412.2017.1306396
Brantly, A. F. (2020). The Evolving Subdiscipline of Cyber Conflict Studies. The Cyber Defense Review, 5(3), 99–120. https://doi.org/10.2307/26954875
Braun, V., & Clarke, V. (2006). Using Thematic Analysis in Psychology. Qualitative Research in Psychology, 3(2), 77–101. https://doi.org/10.1191/1478088706qp063oa
Byrne, D. (2021). A Worked Example of Braun and Clarke’s Approach to Reflexive Thematic Analysis. Quality & Quantity, 56(1), 1391–1412. https://doi.org/https://doi.org/10.1007/s11135-021-01182-y
Cresswell, K., & Williams, R. (2026). Large-scale system-level digitalisation initiatives in the National Health Service in England: insights from three national evaluations. Npj Digital Medicine. https://doi.org/10.1038/s41746-026-02495-8
Damar, M., Özen, A., & Yılmaz, A. (2024). Cybersecurity in The Health Sector in The Reality of Artificial Intelligence, And Information Security Conceptually. Journal of AI, 8(1), 61–82. https://doi.org/10.61969/jai.1466340
Elgabry, M. (2023). Towards cyber-biosecurity by design: an experimental approach to Internet-of-Medical-Things design and development. Crime Science, 12(1). https://doi.org/10.1186/s40163-023-00181-8
Grass, E., Pagel, C., Crowe, S., & Ghafur, S. (2024). A stochastic optimisation model to support cybersecurity within the UK national health service. Journal of the Operational Research Society, 76(7), 1–12. https://doi.org/10.1080/01605682.2024.2436063
Hung. (2025). Multilateral cooperation in building critical infrastructure security and resilience: case of American deterrence of Chinese cyberthreats. Journal of Cyber Policy, 9(3), 1–26. https://doi.org/10.1080/23738871.2024.2443421
Kello, M., Hill, S., Hill, Z., & Stevens, T. (2026). Building NHS Resilience to Ransomware: Central Oversight and Shared Capability Sponsored by White Paper. https://www.kcl.ac.uk/warstudies/assets/building-nhs-resilience-to-ransomware.pdf
Komariah, K., Hamad, I., & Sari, Y. (2025). Cyber Public Relations Management In The Era Of Public Informations Disclosure. Moestopo International Review on Social, Humanities, and Sciences, 5(1), 62–73. https://doi.org/10.32509/mirshus.v5i1.111
Li, J. (2025). Governing High-Risk Technologies in a Fragmented World: Geopolitical Tensions, Regulatory Gaps, and Institutional Barriers to Global Cooperation. Fudan Journal of the Humanities and Social Sciences, 19. https://doi.org/10.1007/s40647-025-00445-4
Manantan, M. B. (2020). The People’s Republic of China’s Cyber Coercion: Taiwan, Hong Kong, and the South China Sea. Issues & Studies, 56(03), 2040013. https://doi.org/10.1142/s1013251120400135
Mauro, M., Noto, G., Prenestini, A., & Sarto, F. (2024). Digital transformation in healthcare: Assessing the role of digital technologies for managerial support processes. Technological Forecasting and Social Change, 209(123781), 123781. https://doi.org/10.1016/j.techfore.2024.123781
Muthuppalaniappan, M., & Stevenson, K. (2020). Healthcare Cyber-Attacks and the COVID-19 Pandemic: an Urgent Threat to Global Health. International Journal for Quality in Health Care, 33(1). https://doi.org/10.1093/intqhc/mzaa117
Neubauer, M., Schick, D., Schreiter, M., Stark, J., Eymann, T., & Schlieter, H. (2026). Bridging digital transformation in public health with digital responsibility. Electronic Markets, 36(1). https://doi.org/10.1007/s12525-025-00868-7
NHS England. (2024). NHS England » Synnovis cyber incident. In www.england.nhs.uk. https://www.england.nhs.uk/synnovis-cyber-incident/
Rajput, K., Darzi, A., & Ghafur, S. (2025). Overlooked and under-reported: the impact of cyberattacks on primary care in the UK National Health Service. The Lancet Digital Health, 7(7), 100879. https://doi.org/10.1016/j.landig.2025.100879
Riggs, H., Tufail, S., Parvez, I., Tariq, M., Khan, M. A., Amir, A., Vuda, K. V., & Sarwat, A. I. (2023). Impact, vulnerabilities, and mitigation strategies for cyber-secure critical infrastructure. Sensors, 23(8), 4060. https://doi.org/https://doi.org/10.3390/s23084060
Schelling, T. C. (1956). An Essay on Bargaining. The American Economic Review, 46(3), 281–306. https://www.jstor.org/stable/1805498
Sharp, T. (2017). Theorizing cyber coercion: The 2014 North Korean operation against Sony. Journal of Strategic Studies, 40(7), 898–926. https://doi.org/10.1080/01402390.2017.1307741
Sinha, R. (2024). The Role and Impact of New Technologies on Healthcare Systems. Discover Health Systems, 3(1), 1–14. https://doi.org/10.1007/s44250-024-00163-w
Sollof, J. (2025). Cyber attack cost Synnovis estimated £32.7m in 2024. In Digital Health. https://www.digitalhealth.net/2025/01/cyber-attack-cost-synnovis-estimated-32-7m-in-2024/
Stoumpos, A. I., Kitsios, F., & Talias, M. A. (2023). Digital Transformation in healthcare: Technology Acceptance and Its Applications. International Journal of Environmental Research and Public Health, 20(4). https://www.mdpi.com/1660-4601/20/4/3407
Synnovis. (2022). About Synnovis. In Synnovis. https://www.synnovis.co.uk/about-synnovis
Synnovis. (2024). Cyber Attack Information Centre. In Synnovis. https://www.synnovis.co.uk/cyberattack-information-centre
Teichmann, F. (2026). International legal responses to ransomware: toward a ban on payments? International Cybersecurity Law Review, 7. https://doi.org/10.1365/s43439-025-00167-z
Toparti, O., Rajput, K., Darzi, A., & Ghafur, S. (2026). Cybersecurity in connected medical devices: a policy agenda for the NHS. Npj Digital Medicine, 9(1), 204. https://doi.org/10.1038/s41746-026-02534-4
Tu, C.-C., Tien, H.-P., & Hwang, J.-J. (2024). Untangling threat perception in international relations: an empirical analysis of threats posed by China and their implications for security discourse. Cogent Arts & Humanities, 11(1). https://doi.org/10.1080/23311983.2024.2335766
Turel, M. (2025). When Cyberattacks Turn Deadly: The Silent Crisis in Healthcare. Neurology India, 73(3), 565–566. https://doi.org/10.4103/neurol-india.neurol-india-d-25-00348
Tytler, J. (2025). Ransomware attack costs Synnovis GBP 32.7 million | Cyber Intelligence Briefing: 24 January 2025. In S-rminform.com. S-RM. https://www.s-rminform.com/cyber-intelligence-briefing/cyber-intelligence-briefing-24-january-2025
Warren, J. (2025). NHS ransomware attack contributed to patient’s death. BBC. https://www.bbc.com/news/articles/cp3ly4v2kp2o
Whyte, C. (2016). Ending cyber coercion: Computer network attack, exploitation and the case of North Korea. Comparative Strategy, 35(2), 93–102. https://doi.org/10.1080/01495933.2016.1176453
Whyte, C., & Etudo, U. (2025). Finding the thieves amongst the liars: Thinking clearly about cyber-enabled influence operations. European Journal of International Security, 1–19. https://doi.org/10.1017/eis.2025.10016
Yin, R. K. (2016). Qualitative research from start to finish (2nd ed.). The Guilford Press PP - New York ; London.
Yin, R. K. (2018). Case Study Research and Applications: Design and Methods (6th ed.). Sage Publications PP - Thousand Oaks, California.
Copyright (c) 2026 Bintang Corvi Diphda, Fahdina Camela Farcha, Nayottama Aryaputra, Sarah Marwah Azzahra, Siti Ni’mah Milly Otolomo

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
Authors retain the copyright and full publishing rights of their articles without restrictions. Authors grant Moestopo International Review on Social, Humanities, and Sciences (MIRSHuS) the non-exclusive right of first publication.









