Ransomware strikes Scottish mental health charity
The RansomEXX cyber criminals have claimed responsibility for the hack which led to more than 12GB of sensitive data being leaked to the dark web


The Scottish Association for Mental Health (SAMH) has confirmed that it has fallen victim to a ransomware attack that has affected its IT systems, including email and some phone lines.
SAMH confirmed to IT Pro that the attack had taken place but is still working to fully understand the incident.
"SAMH is currently dealing with an IT incident, which is affecting our colleagues’ ability to receive and respond to emails across both our national and local service locations,” a statement on its website reads. "Some of our national phone lines are also affected.
“Our local services are still reachable by phone and continue to support service users across Scotland.”
Cyber security researcher Soufiane Tahiri spotted a dark web data dump containing more than 12GB worth of data belonging to the charity on Monday. The gang behind the RansomEXX ransomware strain claimed responsibility by adding SAMH to its victim list.
The data includes sensitive information such as names address, email addresses, and passport scans. Onlookers have described the attack on the charity as “disgusting”.
"We are devastated by this attack," said Billy Watson, chief executive at SAMH to IT Pro. "It is difficult to understand why anyone would deliberately try to disrupt the work of an organisation that is relied on by people at their most vulnerable.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"Our priority is to continue to do everything we can to deliver our vital services. My thanks to our staff team who, under difficult circumstances, are finding ways to keep our support services running to ensure those they support experience as little disruption as possible.
"We are working closely with various agencies including Police Scotland - this is an active investigation. We will continue to take the best expert advice to assist us in effectively dealing with this situation."
IT Pro has asked SAMH for further clarity on the number of individuals affected by the breach and how long it expects disruption to last. This story will be updated when new developments are revealed.
The RansomEXX ransomware was first observed in 2018 but came to prominence in 2020 after a number of high-profile attacks on government departments like the Texas Department of Transportation.
Analysing the ransomware in 2021, cyber security company Cybereason said RansomEXX is typically used in “multi-staged human-operated attacks targeting various government-related entities”.
The ransomware is known for disabling security products to more easily infect a target machine. RansomEXX started on Windows but has more recently evolved to operate a Linux variant too, Cybereason said, though the Linux variant is less complex and lacks certain functionality like disabling security products.
RELATED RESOURCE
Improve security and compliance
Adopting an effective security and compliance risk management approach
RansomEXX is also a file-less ransomware strain, “usually delivered as a secondary in-memory payload without ever touching the disk”.
Other RansomEXX victims include Embraer, one of the largest aircraft manufacturers in the world, Japanese business technology company Konica Minolta, and Brazil’s court system in November 2020.
The cyber criminals behind RansomEXX have also been found to have been targeting flaws in VMware’s ESXi hypervisor in October 2020.

Connor Jones has been at the forefront of global cyber security news coverage for the past few years, breaking developments on major stories such as LockBit’s ransomware attack on Royal Mail International, and many others. He has also made sporadic appearances on the ITPro Podcast discussing topics from home desk setups all the way to hacking systems using prosthetic limbs. He has a master’s degree in Magazine Journalism from the University of Sheffield, and has previously written for the likes of Red Bull Esports and UNILAD tech during his career that started in 2015.
-
Enterprises face delicate balancing act with data center sustainability goals
News High energy consumption, raw material requirements, and physical space constraints are holding back data center sustainability efforts, according to new research from Seagate.
By Emma Woollacott
-
Cleo attack victim list grows as Hertz confirms customer data stolen
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
Cleo attack victim list grows as Hertz confirms customer data stolen – and security experts say it won't be the last
News Hertz has confirmed it suffered a data breach as a result of the Cleo zero-day vulnerability in late 2024, with the car rental giant warning that customer data was stolen.
By Ross Kelly
-
‘Phishing kits are a force multiplier': Cheap cyber crime kits can be bought on the dark web for less than $25 – and experts warn it’s lowering the barrier of entry for amateur hackers
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott
-
Healthcare systems are rife with exploits — and ransomware gangs have noticed
News Nearly nine-in-ten healthcare organizations have medical devices that are vulnerable to exploits, and ransomware groups are taking notice.
By Nicole Kobie
-
Alleged LockBit developer extradited to the US
News A Russian-Israeli man has been extradited to the US amid accusations of being a key LockBit ransomware developer.
By Emma Woollacott
-
February was the worst month on record for ransomware attacks – and one threat group had a field day
News February 2025 was the worst month on record for the number of ransomware attacks, according to new research from Bitdefender.
By Emma Woollacott
-
CISA issues warning over Medusa ransomware after 300 victims from critical sectors impacted
News The Medusa ransomware as a Service operation compromised twice as many organizations at the start of 2025 compared to 2024
By Solomon Klappholz
-
Warning issued over prolific 'Ghost' ransomware group
News The Ghost ransomware group is known to act fast and exploit vulnerabilities in public-facing appliances
By Solomon Klappholz
-
The Zservers takedown is another big win for law enforcement
News LockBit has been dealt another blow by law enforcement after Dutch police took 127 of its servers offline
By Solomon Klappholz