Monetary penalties · General business
Advanced Computer Software Group Limited
What happened
The Information Commissioner’s Office (ICO) has fined Advanced Computer Software Group Ltd (Advanced) £3.07m for security failings that put the personal information of 79,404 people at risk.
Advanced provides IT and software services to organisations, including the NHS and other healthcare providers, and processes people’s personal information on behalf of these organisations.
The fine relates to a ransomware incident in August 2022. Hackers accessed certain systems of Advanced’s health and care subsidiary via a customer account that did not have multi-factor authentication (MFA). The cyber attack was widely reported at the time, with reports of disruption to critical services such as NHS 111, and other healthcare staff unable to access patient records.
Summarised from the notice published by the ICO on 26 March 2025. Read the original notice — it is the authoritative version.
The other end of this
Ransomware crews get in somehow. These are vulnerabilities CISA has tied directly to ransomware campaigns — each one is a live route into an organisation like this one.
- CVE-2026-59310 Broadcom VMware vCenter Path Traversal Vulnerability Broadcom · VMware vCenter
- CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability Cisco · Secure Firewall Management Center (FMC)
- CVE-2026-15409 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability SonicWall · SMA1000 Appliances
- CVE-2026-15410 SonicWall SMA1000 Appliances Code Injection Vulnerability SonicWall · SMA1000 Appliances
- CVE-2026-45659 Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability Microsoft · SharePoint Server