The National Cyber Security Centre warned NHS trusts in England this week that invoice-themed phishing is spiking ahead of flu-season procurement, with lures that mimic vaccine distributors, linen contractors, and agency-staffing portals finance desks already expect to pay in September and October.

What NCSC confirmed

In a sector alert circulated through NHS England’s cyber operations mailing list, NCSC said it had logged more than forty reports from acute trusts since the start of September. The messages typically arrive as PDF attachments or DocuSign-style links referencing purchase orders tied to winter flu clinics, temporary nursing pools, or laundry turnaround for isolation wards. NCSC did not attribute the campaigns to a named group and stressed that some lures may be financially motivated rather than espionage.

Trusts in the Midlands and North West reported the highest volume, though NCSC cautioned that reporting bias may reflect better SOC coverage rather than geography. At least three incidents involved finance users who forwarded messages to shared accounts payable inboxes before IT quarantined the threads—widening the blast radius inside trusts that still route supplier mail through distribution lists.

NHS England’s national cyber security operations centre (CSOC) sat in on the briefing and asked trusts to preserve headers for domains registered in the past thirty days. NCSC published a short checklist: verify bank-detail changes by calling numbers on existing contracts, not numbers in the email body, and treat any request to “rush pay before bank holiday” as a red flag.

How the lures are built

Security teams who shared samples with InfoHandle said the templates quote real NHS supplier names scraped from published spend data and charity annual reports, then swap account numbers at the last page of a multi-page PDF. Several lures referenced “Week 38 agency uplift” language that matches NHS Improvement workforce bulletins, suggesting operators read public workforce guidance rather than breaching procurement systems.

Some messages impersonated cold-chain logistics firms that legitimately ship flu vaccine to GP hubs, complete with fictitious tracking numbers formatted like carrier APIs. Others posed as linen services reminding trusts about isolation-bedding minimums—topics infection-prevention teams discuss openly in board papers. NCSC said none of the samples it reviewed contained malware droppers; the goal appears to be payment diversion, not ransomware deployment.

Trust CISOs noted a timing overlap with finance teams closing September accruals while clinical staff book flu jab clinics. That calendar squeeze is familiar to attackers: in 2024 NCSC flagged similar NHS payroll phishing before winter pressures; this year’s twist is supplier invoices that align with immunisation logistics rather than HR self-service.

Trust and regulator response

NHS England reminded trusts that supplier bank changes should follow existing two-person approval rules and that cyber incident reporting thresholds include attempted payment fraud when patient services could be disrupted. The Information Commissioner’s Office has not opened a formal investigation, but NCSC said trusts should document whether personal data of staff approvers was exposed in forwarded threads.

NCSC urged trusts to enable advanced phishing detection on finance mailboxes, segregate accounts payable from clinical shared drives, and run callback verification drills with procurement—not only IT helpdesks. The centre also pointed trusts to its Exercise in a Box scenarios for finance teams, which several foundation trusts ran last spring after ransomware near-misses.

Banking partners that serve NHS clusters told InfoHandle they are flagging outbound payments to newly created business accounts when payee names resemble known vaccine suppliers. That control depends on trusts not whitelisting “urgent flu stock” narratives that bypass standard supplier master-data updates.

What is still unknown

NCSC has not said how much money, if any, was lost to successful payment diversion this month. Prosecutors have not announced arrests tied to the domains in the alert. It is unclear whether devolved health boards in Scotland and Wales saw parallel templates; NCSC’s notice targeted NHS England trusts but recommended sister agencies share indicators.

Smaller trusts without 24-hour SOCs said they will rely on weekend on-call rotations that may delay domain takedowns. Whether NHS England will mandate out-of-band verification for all supplier bank changes this winter remains undecided; a procurement cyber working group meets after the autumn statement.

For now the measurable shift is tactical: attackers are phishing the invoices trusts expect to pay while flu clinics scale, not the clinical systems that keep patients on wards—and finance desks are being treated as part of the care pathway’s security perimeter.

NCSC plans a follow-up bulletin with anonymised subject-line hashes after October bank holidays so trusts can tune filters without publishing live lure text. Trusts that want direct indicator feeds were told to enroll in NCSC’s Early Warning service if they have not already.

Foundation trust boards said they will add a standing flu-season cyber item to October audit committee packs, pairing infection-prevention metrics with accounts-payable anomaly reports so non-executive directors can see both clinical and financial exposure in one sitting.