A Lockbit ransomware attack against the German hospital network Katholische Hospitalvereinigung Ostwestfalen (KHO) caused service disruptions at three hospitals.
German hospital network Katholische Hospitalvereinigung Ostwestfalen (KHO) announced it has suffered service disruptions at three hospitals (Bielefeld, Rheda-Wiedenbrück, and Herford) after a Lockbit ransomware attack. The security incident could have a serious impact on the local population due to the interruption of the medical emergencies.
The ransomware gang hit the KHO on Christmas Eve and gained access to specifically encrypted data, the organization revealed in a statement published on its website.
KHO shut down the impacted systems to prevent the threat from spreading.
“Unknown persons gained access to the hospitals’ IT infrastructure systems and specifically encrypted data. An initial check showed that it was probably a cyber attack by Lockbit 3.0, the timeline for which cannot yet be predicted. For security reasons, as soon as it became known, all systems were shut down that night and all necessary people and institutions were informed. No information can be given at this time about the extent of the damage or any claims or conditions.” reads the statement published by the organizations.
“We set up a crisis team that night and began analyzing the situation. Access to all systems was immediately blocked. Thanks to our security systems, patient data is still available for patient treatment,” says Dr. Jan Schlenker, Managing Director of KHO gGmbH.
“The responsible authorities have been informed and the internal and external IT security specialists are working hard to clarify the matter and secure all data. “Our security work is in full swing. Patient care is still guaranteed and the clinic continues to operate with slight technical restrictions, but we have withdrawn from emergency care for safety reasons,” said deputy managing director Philipp Herzog.
The organization said that the medical treatments for its patients were not impacted.
Lockbit ransomware gang has yet to add KHO to the list of victims on its Tor leak site
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, German hospital network)