Article Details

Original Article Text

Click to Toggle View

Ransomware attack forces 18 Romanian hospitals to go offline. At least 18 hospitals in Romania were knocked offline after a ransomware attack took down their healthcare management system. The Hipocrate Information System (HIS) used by hospitals to manage medical activity and patient data was targeted over the weekend and is now offline after its database was encrypted. "During the night of 11-12 February 2024, a massive ransomware cyber-attack targeted the production servers running the HIS information system. As a result of the attack, the system is down, files and databases are encrypted," the Romanian Ministry of Health said. "The incident is under investigation by IT specialists, including cybersecurity experts from the National Cyber Security Directorate, and the possibilities for recovery are being assessed. "Exceptional precautionary measures have also been activated for the other hospitals not affected by the attack." The ransomware attack affected various hospitals across Romania, including regional and cancer treatment centers. The list of impacted hospitals shared by the Ministry of Health by the time this article was published includes: At the moment, there is no information on what ransomware operation encrypted the hospitals' medical services management platform or if the patients' personal or medical data was also stolen during the incident. RSC, the company behind the Hipocrate healthcare system, has yet to issue a public statement regarding this incident. A RSC spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today via email and over the phone.

Daily Brief Summary

CYBERCRIME // Ransomware Attack Disrupts 18 Romanian Hospitals' Operations

Ransomware has forced 18 hospitals in Romania to go offline, disrupting services and patient care.

The Hipocrate Information System (HIS), which manages medical activities and patient data, was targeted and encrypted.

The Romanian Ministry of Health stated that the attack occurred overnight between February 11-12, 2024.

National Cyber Security Directorate and IT specialists are investigating and assessing recovery possibilities.

Precautionary measures have been activated in other hospitals not yet affected by this cybersecurity breach.

There is no information available regarding the ransomware group responsible or if patient data was exfiltrated.

The company behind the HIS, RSC, has not made a public statement, and their spokesperson was unavailable for comment.