Ireland’s Health Service Executive (HSE) shut down all its IT systems after a ransomware attack attributed to the Conti group. Hospitals across the country cancelled appointments and returned to paper-based working.
What happened
- The HSE detected the attack in the early hours of 14 May 2021 and switched off its national network as a precaution.
- The Irish government said it would not pay a ransom; the attackers handed over a decryption tool within a week.
- Patient data stolen in the attack was later published online, and the HSE obtained a High Court injunction against sharing it.
- An independent review found the attackers first gained access in March 2021 through a phishing email with a malicious spreadsheet.
Why it mattered
It was one of the most serious cyber attacks on a national health system and exposed long-standing weaknesses in the security of public healthcare IT. The recovery took months, and the HSE later offered compensation to people whose data had been stolen.
Lessons for organisations
Act on security alerts quickly, restrict macros in email attachments, and invest in detection and response so intrusions are found before ransomware is deployed.
Sources: The Register, Krebs on Security
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.