logo

'Major compromise' at NHS temping arm exposed gaping security holes

ID: 8f25a212-b48d-598d-9779-575f2ab65b55

STIX ID: report--8f25a212-b48d-598d-9779-575f2ab65b55

Feed Name: The Register (Security)

Threat Score
78/100

Date Published: 2025-06-12

Date Updated: 2026-04-26

Author: Connor Jones

...
...

In May 2024 NHS Professionals was breached after a compromised Citrix account allowed attackers to escalate privileges to domain admin, move laterally via RDP/SMB/WinRM, and likely exfiltrate the Active Directory database (ntds.dit). Deloitte's incident report documents attempted deployment of Cobalt Strike beacons and other binaries, identifies critical security gaps (lack of MFA on domain accounts, incomplete EDR coverage, limited log retention), and describes remediation actions (AD take-back, password/certificate rotation, disabling Citrix drive mapping) while noting attribution was inconclusive.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.