ctipilot.ch

NHS Blood and Transplant unencrypted pager exposure

incident · incident:nhs-blood-transplant-pager-breach-2026-08 single-source

NHS Blood and Transplant routinely transmitted transplant-patient names, dates of birth, organ types, tissue-match scores and immunosuppression risk factors to hospital transplant teams over an unencrypted pager network, unaware the channel carried no encryption. Disclosed by a BBC investigation on 14 August 2026; NHSBT acknowledged the data breach after being alerted, reported it to the UK Information Commissioner's Office and stopped sending patient data by that route. Because pager broadcasts are one-way and receivers cannot be tracked, NHSBT states it cannot determine whether the data was accessed or how many people are affected (BBC News, 2026-08-14).

Aliases: NHSBT pager breach

Coverage timeline
1
first 2026-08-15 → last 2026-08-15
Peak priority
notable
1 notable
Sources cited
1
1 hosts
Sections touched
1
active-threats
Co-occurring entities
0
no co-occurrence
ATT&CK techniques
1
pinned v19.2 · see below

Hunting pivots

ATT&CK techniques

ATT&CK techniques

1 technique observed across 1 entry — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

Credential Access TA0006

T1040Network Sniffing×1

Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.

Evidence: 2026-08-15/nhsbt-transplant-data-unencrypted-pager-network · ATT&CK page ↗

Discovery TA0007

T1040Network Sniffing×1

Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network. Network sniffing refers to using the network interface on a system to monitor or capture information sent over a wired or wireless connection. An adversary may place a network interface into promiscuous mode to passively access data in transit over the network, or use span ports to capture a larger amount of data.

Evidence: 2026-08-15/nhsbt-transplant-data-unencrypted-pager-network · ATT&CK page ↗

Story timeline

  1. 2026-08-15NHS Blood and Transplant sent organ-offer messages naming recipients over an unencrypted pager network — and because pager broadcasts leave no receiver log, it cannot scope who received them
    active-threatsA BBC investigation forces NHSBT to report a breach: transplant-patient identifiers broadcast in clear over a legacy paging network

Where this entity is cited

  • active-threats1

Source distribution

  • bbc.co.uk1 (100%)

explore in graph

Entries about NHS Blood and Transplant unencrypted pager exposure (1)

2026-08-15 · view entry permalink →

NOTABLENATOB2

NHS Blood and Transplant sent organ-offer messages naming recipients over an unencrypted pager network — and because pager broadcasts leave no receiver log, it cannot scope who received them

A BBC investigation established that NHS Blood and Transplant — the service that coordinates organ transplants across the UK — routinely sent the names, dates of birth and the types of organs being offered or needed to members of hospital transplant teams using pagers, unaware the messages were not encrypted (BBC News, 2026-08-14). The messages also carried tissue-match scores and immunosuppression risk factors for the people receiving transplants. NHSBT acknowledged this was a data breach after being alerted by the BBC, said it was "deeply sorry", reported the breach to the Information Commissioner and has stopped sending patient data this way; its head of organ transplantation, Anthony Clarkson, said the service had been using the channel for urgent communications where speed can be critical, and that "We were surprised that these messages were not encrypted, and that vulnerability was there." The ICO confirmed NHSBT reported an incident and that it is making inquiries (BBC News, 2026-08-14).

The property that makes this different from an ordinary disclosure is the absence of a receiver-side record. Paging is a one-way broadcast: the BBC reports NHSBT's position that because recipients of pager messages cannot be tracked, it is unclear whether the unencrypted information was accessed or how many people may have been affected (BBC News, 2026-08-14). Luca Arnaboldi, an assistant professor at the University of Birmingham quoted in the investigation, described the technology as "never meant for privacy", noted that a broadcast reaches anyone on the right frequency across a wide area, and characterised the result as "an unauditable log of leaked information". The exposure was not limited to NHSBT: over a ten-day sample the BBC found hundreds of messages on the same network from ambulance trusts, hospitals and fire services, including mental-health incident details, medication details and the name of a patient trying to take their own life. North West Ambulance Service and Northern Ireland Ambulance Service, both named as users, said their messages did not include patients' names; NWAS said pagers have now been fully withdrawn (BBC News, 2026-08-14).

Responsibility here sits with configuration rather than with a defect. The company operating the paging network told the BBC it provides encrypted paging and secure-messaging solutions with "customers determining how those services are deployed", that it has no visibility of or control over the content its customers transmit, and that its terms make clear radio signals may be intercepted and advise customers not to send sensitive or personal information over radio (BBC News, 2026-08-14). In 2019 the then-Health Secretary, Matt Hancock, announced that the NHS in England should stop using pagers by 2021, and parts of the organisation continued regardless; the Department for Health said that where "legacy technologies" are still in use, patient information should be "handled securely and in line with data protection requirements" (BBC News, 2026-08-14).

The sensitive medical data of transplant patients from across the UK was routinely sent over an unencrypted pager network, an NHS service has admitted.

Recipients of pager messages cannot be tracked, therefore NHSBT said it was unclear whether the unencrypted information was accessed or how many people may have been affected.

BBC News 2026-08-14
incident15 Aug 04:49Zsingle-sourceOpen finding ↗
Sources: BBC News