Barts Health NHS discloses data breach following Oracle zero-day hack

Barts Health NHS discloses data breach following Oracle zero-day hack

By Bill Toulas
Publication Date: 2025-12-05 18:55:00

Barts Health NHS Trust, a major healthcare provider in England, announced that Clop ransomware actors stole files from one of its databases after exploiting a vulnerability in its Oracle E-Business Suite software.

The stolen data included several years of invoices showing the full names and addresses of people who paid for treatments or other services at Barts Health Hospital.

Information about former employees who owed money to the trust and suppliers whose details are already public was also disclosed, the organization said.

In addition to Barts’ files, the compromised database contains files relating to accounting services the trust has provided to Barking, Havering and Redbridge University Hospitals NHS Trust since April 2024.

The Cl0p ransomware published the stolen information on its leak portal on the dark web.

“The theft occurred in August, but until November, when the files were released in the dark, there was no indication that the trust data was compromised…”