https://www.theregister.com/2025/06/12/compromise_nhs_professionals/
Exclusive Cybercriminals broke into systems belonging to the UK’s NHS Professionals body in May 2024, stealing its Active Directory database, but the healthcare organization never publicly disclosed it, The Register can reveal. … The attack was detected on May 15, 2024, and Deloitte said the criminals behind it broke in using a compromised Citrix account. The investigators were not able to figure out how that account, named “LMS.Support2,” became compromised. …
Very detailed breakdown of the HOWS, compared to other breach stories I’ve read, which I really like.
Regards