Authorities in Romania confirmed that a ransomware attack that targeted the Hipocrate Information System (HIS) has disrupted operations for at least 100 hospitals.
Hipocrate Information System (HIS) is a software suite designed to manage the medical and administrative activities of hospitals and other healthcare institutions.
The attack took place on February 11 and encrypted data in the production servers.
“During the night of February 11 to 12, 2024, a massive cyber ransomware attack took place on the production servers on which the HIS IT system runs. As a result of the attack, the system is down, files and databases are encrypted.” reported the Romanian Ministry of Health.
The initial number of impacted hospitals was 21, but later the authorities confirmed that the number had increased to 25. Another 79 hospitals took their systems down as a precautionary measure.
Romanian Ministry of Health added that cybersecurity specialists, including cybersecurity experts from the National Cyber Security Directorate, are monitoring the situation. The Romanian government also announced extraordinary preventive measures to prevent other hospitals from being impacted by the incident.
DNSC reported that ransomware operators employed a variant of the Phobos ransomware family known as Backmydata ransomware. The threat actors demand the payment of 3.5 BTC (about 157,000 EURO).
“Hospitals using the HIPOCRATE platform, regardless of whether they were affected or not, have since yesterday received a series of recommendations from the DNSC to properly manage the situation” reported DNSC.
At this time, it is still unclear if the threat actors have stolen sensitive data from the impacted organizations.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – ransomware, Romanian hospitals)