---
title: "Two NHS Trusts Hit: Ivanti vulnerability | Firevault"
description: "Two major NHS trusts, University College London Hospitals NHS Foundation Trust and University Hospital Southampton NHS Foundation Trust, have been exposed in a…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": "GB"
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Firevault has rewritten the rules for data protection & storage via its offline secure storage (OSS) platform, for users to vault everything that matters.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/two-nhs-trusts-targeted-in-sophisticated-cyberattack-exploiting-ivanti-vulnerability#webpage",
      "url": "https://fire-vault.com/news/two-nhs-trusts-targeted-in-sophisticated-cyberattack-exploiting-ivanti-vulnerability",
      "name": "Two NHS Trusts Hit: Ivanti vulnerability",
      "description": "Two major NHS trusts, University College London Hospitals NHS Foundation Trust and University Hospital Southampton NHS Foundation Trust, have been exposed in a…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/dda25748-291d-47c3-a739-b063f60260c4/nhs-trusts-ivanti-attack-1771248366184-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/two-nhs-trusts-targeted-in-sophisticated-cyberattack-exploiting-ivanti-vulnerability#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/two-nhs-trusts-targeted-in-sophisticated-cyberattack-exploiting-ivanti-vulnerability#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Two NHS Trusts Targeted via Ivanti Vulnerability",
          "item": "https://fire-vault.com/news/two-nhs-trusts-targeted-in-sophisticated-cyberattack-exploiting-ivanti-vulnerability"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Two NHS Trusts Targeted via Ivanti Vulnerability",
      "description": "Two major NHS trusts, University College London Hospitals NHS Foundation Trust and University Hospital Southampton NHS Foundation Trust, have been exposed in a…",
      "url": "https://fire-vault.com/news/two-nhs-trusts-targeted-in-sophisticated-cyberattack-exploiting-ivanti-vulnerability",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/dda25748-291d-47c3-a739-b063f60260c4/nhs-trusts-ivanti-attack-1771248366184-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/dda25748-291d-47c3-a739-b063f60260c4/nhs-trusts-ivanti-attack-1771248366184-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/dda25748-291d-47c3-a739-b063f60260c4/nhs-trusts-ivanti-attack-1771248366184-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/dda25748-291d-47c3-a739-b063f60260c4/nhs-trusts-ivanti-attack-1771248366184-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2025-05-28T22:55:44+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/two-nhs-trusts-targeted-in-sophisticated-cyberattack-exploiting-ivanti-vulnerability"
      },
      "inLanguage": "en-GB",
      "articleSection": "News",
      "wordCount": 413,
      "keywords": "News, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Two major NHS trusts, University College London Hospitals NHS Foundation Trust and University Hospital Southampton NHS Foundation Trust , have been exposed in a newly identified cyberattack, after threat actors exploited a vulnerability in a widely used device management platform. The breach, linked to Ivanti Endpoint Manager Mobile (EPMM) , enabled attackers to gain unauthorised access to interna",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2025
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)[2026 PowerSchool 62.4M records ](https://www.bleepingcomputer.com)[2026 DISA Global Solutions 3.3M records ](https://techcrunch.com)[2026 Globe Life 850K records ](https://www.securityweek.com)[2026 Lidl GB Customer contact data ](https://www.theguardian.com/business/2026/jun/11/lidl-gb-third-party-data-breach)[2026 Asahi Group Production systems disrupted ](https://www.reuters.com/technology/cybersecurity/asahi-says-cyberattack-disrupted-operations-japan-2025-09-29/)[2026 Kido International 8K records ](https://www.bbc.co.uk/news/articles/c623d7v0e5xo)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](https://www.bbc.co.uk/news/articles/c789e7l1z7po)[2026 Jaguar Land Rover Production and IT systems disru... ](https://www.bbc.co.uk/news/articles/cx2gx8p3rzeo)[2026 Peter Green Chilled Order and logistics data ](https://www.bbc.co.uk/news/articles/c0k7yy8n3g5o)[2026 Adidas UK Customer contact details ](https://www.bbc.co.uk/news/articles/c78jkev1el2o)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · 28 May 2025 

# Two NHS Trusts Targeted via Ivanti Vulnerability

Two major NHS trusts, University College London Hospitals NHS Foundation Trust and University Hospital Southampton NHS Foundation Trust, have been exposed in a…

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

3 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ftwo-nhs-trusts-targeted-in-sophisticated-cyberattack-exploiting-ivanti-vulnerability)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ftwo-nhs-trusts-targeted-in-sophisticated-cyberattack-exploiting-ivanti-vulnerability&text=Two%20NHS%20Trusts%20Targeted%20via%20Ivanti%20Vulnerability%0A%0ATwo%20major%20NHS%20trusts%2C%20University%20College%20London%20Hospitals%20NHS%20Foundation%20Trust%20and%20University%20Hospital%20Southampton%20NHS%20Foundation%20Trust%2C%20have%20been%20exposed%20in%20a%E2%80%A6)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Ftwo-nhs-trusts-targeted-in-sophisticated-cyberattack-exploiting-ivanti-vulnerability)[](mailto:?subject=Two%20NHS%20Trusts%20Targeted%20via%20Ivanti%20Vulnerability&body=Two%20major%20NHS%20trusts%2C%20University%20College%20London%20Hospitals%20NHS%20Foundation%20Trust%20and%20University%20Hospital%20Southampton%20NHS%20Foundation%20Trust%2C%20have%20been%20exposed%20in%20a%E2%80%A6%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Ftwo-nhs-trusts-targeted-in-sophisticated-cyberattack-exploiting-ivanti-vulnerability)

![A hospital building exterior at blue hour with emergency lighting and visible infrastructure](/__l5e/assets-v1/dda25748-291d-47c3-a739-b063f60260c4/nhs-trusts-ivanti-attack-1771248366184-2x.jpg)

A hospital building exterior at blue hour with emergency lighting and visible infrastructure

Why it matters

## What this means for organisations holding critical data

Two major NHS trusts, University College London Hospitals NHS Foundation Trust and University Hospital Southampton NHS Foundation Trust, have been exposed in a…

In this analysis

**On this page**

Two major NHS trusts, [University College London Hospitals NHS Foundation Trust](https://www.uclh.nhs.uk/) and [University Hospital Southampton NHS Foundation Trust](https://www.uhs.nhs.uk/), have been exposed in a newly identified cyberattack, after threat actors exploited a vulnerability in a widely used device management platform.

The breach, linked to [Ivanti Endpoint Manager Mobile (EPMM)](https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US), enabled attackers to gain unauthorised access to internal systems. Security analysts confirm that this was not a ransomware event, but a stealth intrusion designed to extract sensitive information without triggering standard alarms.

The software in question is commonly deployed across enterprise and public sector environments to manage and secure employee mobile devices. In this instance, attackers exploited a known flaw to infiltrate network environments and access data silently.

Cybersecurity experts warn that the incident could result in the exposure of highly sensitive patient records and operational data.

“This represents a clear example of the growing threat posed by software-based vulnerabilities, especially in systems that underpin large, distributed networks such as those used in healthcare,” one analyst stated. “The data wasn’t locked, it was taken, quietly.”

The breach forms part of a broader campaign affecting organisations in the UK, Europe, the US, and Asia, with victims spanning healthcare, government, and commercial sectors.

**A Wake-Up Call for Healthcare Security**

The attack highlights a shift in tactics from disruptive ransomware to clandestine data harvesting, where the goal is no longer to shut down systems but to extract valuable information unnoticed.

With investigations ongoing, NHS security teams and national cybersecurity authorities are assessing the scope of the breach and issuing guidance to mitigate further exposure.

There is currently no confirmation of the volume or type of data accessed, and both trusts have yet to issue formal public statements.

**Exploring Offline Alternatives**

As cyber threats grow increasingly sophisticated, some organisations are beginning to reconsider the default assumption that all data must remain connected. Solutions such as [Firevault](/) a fully offline digital vault are gaining attention for offering a fundamentally different approach: disconnecting critical files from the internet entirely.

By physically isolating sensitive digital assets, Firevault aims to render data invisible and inaccessible to remote attackers, regardless of how advanced their intrusion methods may be. In a climate where exploits can sit undetected for months, offline storage is becoming part of a wider conversation around resilience and patient data protection.

This latest breach reinforces the urgency for healthcare providers to not only patch software and strengthen monitoring, but also rethink their exposure surface and ask what truly needs to stay online.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## Physical disconnection removes the path an attacker needs

Offline Secure Storage® holds a clean copy of your data on hardware that is physically disconnected, so an intrusion cannot reach it, encrypt it or delete it.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your data sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Command**Access windows and retrieval under your control 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Firevault Awarded Cyber Essentials and Cyber Essentials Plus Certification](/__l5e/assets-v1/446b675b-b48b-4b8e-ba01-b97ad3abf97d/firevault-cyber-essentials-plus-certified-2x.jpg)

News 

### Firevault Awarded Cyber Essentials and Cyber Essentials Plus Certification

Firevault has been awarded Cyber Essentials and Cyber Essentials Plus certification, the UK Government-backed scheme run by the NCSC, following an independent technical audit of its systems and controls.

26 Jul 2026 2 min 







](/news/firevault-cyber-essentials-plus-certified)[

![Russian hackers steal UK government logins: why offline vaults change the equation](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Frussian-hackers-uk-government-logins.jpg)

News 

### Russian hackers steal UK government logins: why offline vaults change the equation

The Telegraph reports that Russian-linked hackers have harvested UK government login credentials and traded them on dark-web forums. The incident is a reminder that credentials, however well protected in the cloud, remain the single point of failure that offline data vaults are designed to remove.

7 Jul 2026 4 min 







](/news/russian-hackers-steal-uk-government-logins-offline-vaults)[

![Great Marlow School partially closed after cyber attack](/news/great-marlow-school-cyber-hero.jpg)

News 

### Great Marlow School partially closed after cyber attack

A malware incident has shut down ICT systems at Great Marlow School in Buckinghamshire, cancelling lessons and silencing parent communications. Here is what it tells us.

14 Jun 2026 4 min 







](/news/great-marlow-school-cyber-attack-partial-closure)[

![School Ransomware: Files Must Live Offline](/__l5e/assets-v1/5dcdf155-e287-48e8-bf9b-82b9837b80d0/school-ransomware-safeguarding-2x.jpg)

News 

### School Ransomware: Files Must Live Offline

St Anne's Catholic School in Southampton was shut for four days after ransomware hit its network. It is not the first school to be targeted. From nurseries to councils, sensitive safeguarding data remains dangerously exposed on connected systems.

27 Mar 2026 7 min 







](/news/st-annes-southampton-ransomware-safeguarding-files-physically-offline)[

![TfL Hack: 10 Million Records Stolen](/__l5e/assets-v1/77ff397a-d530-4aee-88e3-5098513ae34e/tfl-hack-10-million-scattered-spider-2x.jpg)

News 

### TfL Hack: 10 Million Records Stolen

Transport for London has confirmed that around 10 million customer records were stolen during the 2024 Scattered Spider cyber attack, making it one of the largest data breaches in British history. The revelation raises urgent questions about transparency, regulatory accountability and the case for offline secure storage.

11 Mar 2026 5 min 







](/news/tfl-hack-10-million-records-stolen-scattered-spider)[

![Firevault: 2025 Tech Trailblazers Shortlist](/__l5e/assets-v1/c2acabab-9ada-4969-9d69-b18478181083/firevault-shortlisted-trailblazers-v2-1771248067838-2x.jpg)

News 

### Firevault: 2025 Tech Trailblazers Shortlist

We’re proud to announce that Firevault Limited has been shortlisted for the 2025 Tech Trailblazers Awards, recognised in the Firestarter category. For a young…

29 Nov 2025 6 min 







](/news/firevault-shortlisted-for-the-2025-tech-trailblazers-firestarter-award)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/offline-secure-storage/what-is-oss)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)