When a cyber attack took 100 hospitals offline - BBC World Service
By BBC World Service
Key Concepts
- Ransomware: A type of malicious software (malware) that encrypts a victim's files, rendering them unreadable, with attackers demanding payment for a decryption key.
- Hipocrate Information System: A centralized medical software platform used by Romanian hospitals for patient admissions, pharmacy logistics, payroll, and clinical records.
- DNSC (Directorate National Cyber Security): Romania’s national cybersecurity authority responsible for incident response and coordination.
- Backups: Copies of data stored separately, essential for restoring systems after a ransomware attack without paying the ransom.
- Exfiltration: The unauthorized transfer of data from a computer or network, often used as leverage by hackers to threaten victims.
- Affiliate Model: A business-like structure in cybercrime where developers create malware and "affiliates" carry out the actual attacks, often sharing profits.
1. The Incident: A Coordinated Attack on Healthcare
The attack targeted the Hipocrate Information System, a critical software suite used by numerous Romanian hospitals. By infiltrating this central provider, hackers were able to compromise multiple facilities simultaneously.
- The Trigger: The attack began over a weekend, with staff at Pitesti Children’s Hospital noticing system errors. By Monday morning, the scale became clear: 26 hospitals were offline.
- The Ransom: Files were renamed to "BACKMYDATA," and attackers demanded 3.5 Bitcoins (approximately €160,000) for the decryption key.
- The Response: The DNSC issued an immediate directive to all hospitals to disconnect from the internet to prevent further spread.
2. Operational Impact and Challenges
The loss of the Hipocrate system paralyzed hospital operations, forcing staff to revert to manual, paper-based workflows.
- Clinical Disruption: Doctors lost access to laboratory results, radiology images, and pharmacy inventory.
- Staff Stress: Medical personnel faced immense pressure, dealing with both the technical failure and the frustration of patients who were unable to receive timely care.
- Data Loss: While many hospitals had backups, some were outdated, leading to significant data gaps that required weeks of manual reconstruction from paper records.
3. Methodology and Strategic Response
The Romanian response is considered a "blueprint" for handling large-scale cyber incidents due to the following actions:
- Refusal to Negotiate: The DNSC explicitly advised hospitals not to pay the ransom. They argued that paying does not guarantee data recovery, may lead to further extortion (via data exfiltration), and finances criminal enterprises.
- Containment: Cyber experts worked through the night with the software provider to isolate the breach and remove the hackers from the central system.
- Resilience and Workarounds: Hospitals implemented offline methods, such as using Excel and email for lab results, to ensure patient safety. Remarkably, no deaths or serious harm were recorded during the incident.
4. Comparative Context and Global Trends
The report highlights a shift in the nature of cybercrime:
- Evolution of Morality: Unlike the 2017 WannaCry attack (a global virus) or the 2021 Irish hospital hack (where hackers provided a free key after realizing they hit a hospital by mistake), modern attacks are deliberate and targeted.
- Escalating Risks: The report cites the 2024 London blood testing hack (Synnovis), which resulted in at least one patient death, illustrating the lethal potential of these attacks.
- International Cooperation: While the specific perpetrators of the Romanian attack remain under investigation, international police operations have recently dismantled related ransomware gangs, leading to arrests in countries that cooperate with Western law enforcement.
5. Notable Quotes
- "Paying ransom does not guarantee that cyber criminals will provide you with the decryption key. And even if they do, that doesn't mean that your data will not be exfiltrated and will not be sold on the dark web or reused." — Representative from the DNSC.
- "It's very, very important not to finance the phenomenon." — DNSC on the policy of refusing ransom payments.
6. Synthesis and Conclusion
The Romanian hospital hack serves as a critical case study in national cyber resilience. The primary takeaways are:
- Digitization Increases Risk: As healthcare systems become more technologically advanced, they become more vulnerable to systemic failure.
- Preparation is Paramount: The existence of up-to-date, offline backups was the single most important factor in recovery.
- Solidarity and Drills: The success in Romania was attributed to national coordination, clear communication from the DNSC, and the ability of medical staff to adapt under pressure.
- Policy Stance: A firm, government-backed refusal to pay ransoms is essential to discourage future targeting of critical infrastructure.
Chat with this Video
AI-PoweredLoad the transcript when you're ready to chat so the initial page stays lighter.
Related Videos

Cyberattacks, data encryption, extortion - How cybercriminals operate | DW Documentary
DW Documentary

Guthrie family issues message to potential kidnappers: 'We want to talk to you'
ABC News

Emerging Cybersecurity Threats by Igor Opushnyev & Kostiantyn Nikolaiev
Canadian Institute for Cybersecurity (CIC)