• News/
  • https://www.bleepingcomputer.com/news/security/barts-health-nhs-discloses-data-breach-after-oracle-zero-day-hack/

Barts Health NHS discloses data breach after Oracle zero-day hack

BleepingComputer
·
Bill Toulas
·
Published Dec 5, 2025
·
Updated

Barts Health NHS Trust, a major healthcare provider in England, announced that Clop ransomware actors have stolen files from one of its databases after exploiting a vulnerability in its Oracle E-business Suite software. The stolen data are invoices spanning several years that expose the full names and addresses of individuals who paid for treatment or other services at Barts Health hospital. Information of former employees who owed money to the trust, and suppliers whose data is already public, has also been exposed, the organization says. In addition to Barts' files, the compromised database include files concerning accounting services the trust provided since April 2024 to Barking, Havering, and Redbridge University Hospitals NHS Trust. Cl0p ransomware has leaked the stolen information on their leak portal on the dark web. "The theft occurred in August, but there was no indication that trust data was at risk until November when the files were posted on the dark web," explained Barts. "To date no information has been published on the general internet, and the risk is limited to those able to access compressed files on the encrypted dark web." The hospitals operator stated that it is in the process of getting a High Court order to ban the publication, use, or sharing of the exposed data by anyone, though such orders have limited effect in practice. Barts Health NHS Trust runs five hospitals throughout the city of London, namely Mile End Hospital, Newham University Hospital, ...

Read full article

Affected Software

1 affected component
Oracle E-Business Suite

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a data breach at Barts Health NHS Trust due to a zero-day exploit in Oracle E-business Suite software.

2

What security implications are discussed in the article?

The breach highlights the risks associated with vulnerabilities in widely-used software, specifically the potential for ransomware attacks.

3

What group is responsible for the breach mentioned in the article?

The breach was carried out by the Clop ransomware group.

4

What types of data were compromised in this incident?

Files were stolen from one of Barts Health's databases, although specific types of data were not disclosed.

5

What software was exploited in the Barts Health NHS data breach?

The vulnerability was in the Oracle E-business Suite software, which was exploited by the attackers.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203