October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Advanced fined £3.07m over LockBit attack that disrupted NHS 111 services

The ICO’s final £3.07m penalty against Advanced follows a 2022 LockBit attack that disrupted Adastra-based NHS 111 services and exposed sensitive care data. The case establishes why processors need complete MFA, patching and segmentation controls.
From TheFinanceBase Team5 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Advanced Computer Software Group—now trading as OneAdvanced—was fined £3.07 million by the UK Information Commissioner’s Office (ICO) on 27 March 2025 after a LockBit ransomware attack in August 2022 disrupted healthcare services using its Adastra platform. The final enforcement concerned personal data relating to 79,404 people and included information that could reveal how to enter the homes of 890 people receiving care at home.

What happened, in brief

LockBit attackers used legitimate credentials belonging to a third-party customer account. Multifactor authentication (MFA) was not enabled on that account. The attackers used remote access to reach a Staffplan Citrix server, moved through Advanced’s environment, escalated privileges, stole data and deployed ransomware.

The incident cut affected customers’ access to Adastra, a clinical-management system used for NHS 111 and other frontline functions. Disrupted workflows included ambulance dispatch, emergency prescriptions, out-of-hours patient services and referrals. This was a supplier compromise with downstream clinical-service effects; the available evidence does not show that every NHS 111 service in the country stopped operating.

The case matters beyond the outage. The ICO imposed the penalty on a data processor, reinforcing that a technology supplier can face direct data-protection enforcement for its own security failures even when NHS organisations remain the data controllers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Read the final-penalty reporting from Computer Weekly.

Why Advanced’s software was important to NHS services

Advanced supplied software to NHS trusts, social-care organisations and other healthcare bodies. The affected product areas included:

  • Adastra: clinical patient-management software supporting NHS 111 and related services.
  • Staffplan: care-staff rostering.
  • Caresys: care-home management.

When access to Adastra was lost, organisations using the platform had to work around unavailable systems and workflows. The operational effect therefore depended on which services each customer used; “NHS 111 was crippled” is an imprecise shorthand for disruption affecting users of the platform, not proof of a uniform nationwide shutdown.

How the August 2022 attack unfolded

  1. A third-party customer account with legitimate credentials was used to gain entry.
  2. The account did not have MFA enabled.
  3. The attackers established an RDP session on a Staffplan Citrix server.
  4. They moved laterally through Advanced’s environment and escalated privileges.
  5. Sensitive information was exfiltrated.
  6. LockBit ransomware was executed, disrupting customer access to services.

This sequence reflects the ICO findings as reported by Computer Weekly rather than a publicly released, complete forensic report. The key control failure was not simply the existence of remote access; it was the combination of an externally usable account, incomplete authentication protection and insufficient containment of the wider environment.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What data was exposed?

The final enforcement account identified data relating to 79,404 people. The ICO specifically highlighted information that could help someone gain access to the homes of 890 home-care recipients, making the incident a physical-safety concern as well as a confidentiality issue.

Earlier reporting described affected information as including patient medical records and telephone numbers. Advanced said that NHS Trust-controlled patient data was not impacted, that no data was made public and that it had found no evidence of fraud or misuse. Those are the company’s reported positions; they should not be treated as an independent finding that misuse was impossible.

Advanced also reported that 16 customers had data exfiltrated. The final total of 79,404 people differs from the provisional figure of 82,946 because the ICO’s assessment changed before the final decision; the two numbers relate to different stages of the enforcement process.

From a proposed £6.09m penalty to the final £3.07m fine

Date Status What it meant
August 2022 LockBit attack Access to affected Advanced services was disrupted and data was stolen.
7 August 2024 Provisional Notification of Intent The ICO proposed a potential £6.09m penalty concerning data relating to 82,946 people. Advanced could make representations; this was not a final penalty.
27 March 2025 Final enforcement The ICO fined Advanced £3.07m, citing data relating to 79,404 people.

Advanced made representations after the provisional notice. The ICO considered the company’s remediation and cooperation with the ICO, NHS, National Cyber Security Centre and National Crime Agency. Advanced accepted a voluntary settlement and did not appeal. The final figure was therefore lower than the initial proposal, but it remained a substantial data-protection penalty.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why the ICO held the processor responsible

Under UK GDPR, a controller decides why and how personal data is processed. A processor handles data on the controller’s instructions. Processors nevertheless have their own obligations to implement appropriate technical and organisational security measures.

Advanced’s healthcare subsidiary was the processor operating systems for customer organisations. The ICO found that its controls were not appropriate to the risk. The case was described as the ICO’s first penalty of this kind against a data processor, giving the decision significance for outsourced healthcare and technology providers.

The ICO’s explanation of the two roles and processor responsibilities is available in its controller and processor guidance.

The security weaknesses identified

  • Incomplete MFA coverage: MFA existed in parts of the organisation but did not cover every externally reachable account.
  • Vulnerability-management gaps: scanning and prioritisation were not sufficient to identify and reduce exploitable weaknesses.
  • Patch-management shortcomings: the organisation lacked consistently effective processes for applying security updates.
  • Inconsistent external-connection controls: externally accessible pathways were not secured to a uniform standard.

The practical lesson is broader than “turn on MFA.” Healthcare suppliers need an auditable inventory of every customer, supplier and privileged account; proof that MFA coverage has no unmanaged exceptions; tightly restricted and monitored RDP or Citrix access; and evidence that vulnerabilities are remediated within risk-based deadlines.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Advanced’s response and the cost of recovery

Advanced said it isolated systems after detecting suspicious activity and cooperated with investigators and customers. It reported no public release of the data and no evidence of fraud or misuse. It also said NHS Trust-controlled patient data was not impacted.

Computer Weekly reported from Advanced’s accounts that the company spent £18.3m on remediation after the attack and a further £3m in the 2023–24 financial year. These are reported accounting-period expenditures, not a guaranteed measure of the incident’s total lifetime cost.

The company’s filing history is available through Companies House.

What healthcare suppliers should change

Make identity controls complete

  • Inventory every external, customer and supplier account.
  • Require phishing-resistant or otherwise strong MFA wherever technically possible.
  • Review dormant accounts, shared credentials and exceptions through a documented approval process.
  • Use privileged-access management and limit administrative rights.

Reduce the blast radius

  • Segment clinical applications, management networks and remote-access infrastructure.
  • Restrict RDP and Citrix exposure by network, device, time and role.
  • Monitor lateral movement and privilege escalation, not only malware alerts.
  • Test that compromise of one customer pathway cannot provide broad access to the estate.

Make vulnerability and recovery controls measurable

  • Maintain complete asset visibility and run regular vulnerability scans.
  • Set patch service-level targets based on severity and exposure, then retain evidence of completion.
  • Keep tested, offline or otherwise ransomware-resilient backups.
  • Define recovery objectives for clinical workflows, not just infrastructure.

Plan jointly with customers

  • Agree incident-notification routes, decision rights and technical contacts in advance.
  • Exercise continuity plans for NHS 111, dispatch, prescriptions, referrals and out-of-hours care.
  • Give customers evidence that contractual security promises operate in production, including subcontractor and remote-access controls.

Why this case still matters

The August 2022 incident shows how a supplier can become a patient-safety and public-service dependency. Availability failures can disrupt care even when records are not permanently altered, while stolen information can create risks for people receiving care at home. The March 2025 penalty also makes clear that being a processor does not place security responsibility solely on the NHS customer: suppliers have direct obligations, and inadequate controls can lead to direct ICO enforcement.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.