
NHS Dumfries and Galloway said it recently experienced a cyber security incident that affected daily operations and gave hackers access to “a significant quantity of data”.
Associated with NHS Scotland, NHS Dumfries and Galloway serves Scotland’s Dumfries and Galloway region and has 11 hospitals under its wing, including the main Dumfries and Galloway Royal Infirmary in Dumfries.
In a statement published on its website, NHS D&G said that it recently experienced a cyber attack that disrupted certain operations. The board immediately launched an internal investigation, with assistance from external cyber security experts, to understand the nature and scope of the incident.
The trust is working with partner agencies including Police Scotland, the National Cyber Security Centre and the Scottish Government to resolve the situation.
While the investigation is still ongoing, NHS D&G believes that the sensitive personal data of its staff and patients were accessed during the incident.
“During these incursions into our systems, there is a risk that hackers have been able to acquire a significant quantity of data. Work is continuing together with cyber security agencies to investigate what data may have been accessed, but we have reason to believe that this could include patient-identifiable and staff-identifiable data,” the NHS board said.
“Breach of confidential data is an incredibly serious matter. We are encouraging everyone, staff and public, to be on their guard for any attempt to access their systems or approaches from anyone claiming to be in possession of data relating to them,” it added.
A Police Scotland spokesperson said that the department is working with the health board and assisting it with the investigation. “Enquiries are continuing into a cyber attack on NHS Dumfries and Galloway,” the spokesperson added.
In a statement shared with the media, Neil Gray, the health secretary of the Scottish government, said, “There are well established procedures for dealing with a situation of this kind.
“We are providing assistance and support to NHS Dumfries and Galloway as they handle this incident, and NHS NSS (National Services Scotland) is engaging with the rest of NHS Scotland and providing updates as necessary.”
A spokesperson for the National Cyber Security Centre (NCSC) added, “We are working with law enforcement, NHS Scotland and the Scottish government to fully understand the impact of the incident.”
NHS D&G is yet to share details on who is behind the cyber attack, or the nature of the attack. It has, however, assured patients and staff that it will share more details about the incident on a dedicated webpage as and when available.
The cyber attack coincided with serious financial constraints faced by the NHS trust which has affected quality of service offered to patients in the Dumfries and Galloway region. The trust announced in February that it faces a "very stark financial situation" due to which its opening financial position in April 2024 will be a deficit of £35 million.
“Without any cost savings being made, this overspend could potentially rise to around £54 million at the end of March 2025 because of inflation, growing patient need and increasing costs involved in providing treatment and care. This is clearly unsustainable,” said chief executive Jeff Ace.
“NHS Dumfries and Galloway have agreed with the Scottish Government that we are required to reduce the deficit to £25 million by the end of March 2025 which equates to achieving savings of £29 million within the coming financial year.
“These savings are likely to impact on our workforce, our infrastructure and our ways of delivering services. While we will do everything we can to mitigate the impact, we recognise that our services will feel different for our staff, patients and communities,” he added.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543