Don’t do SECURITY. Do business SECURELY.

Ransomware attack cripples Düsseldorf University Hospital

A ransomware attack forces Düsseldorf University Hospital to turn away emergency patients, prompting a police investigation.

A ransomware attack on Düsseldorf University Hospital in Germany disrupted its IT systems and forced it to deregister from emergency care. German prosecutors opened an investigation after a critically ill patient, diverted to a hospital in Wuppertal, died.

What happened

  • The attackers exploited a vulnerability in Citrix software for which a fix had been available since early 2020.
  • The ransom note was reportedly addressed to the affiliated Heinrich Heine University; when police contacted the attackers, they provided a decryption key.
  • The hospital postponed operations and outpatient treatment while systems were restored.
  • Prosecutors later concluded the patient’s condition was so severe she would have died regardless, so the attack was not the cause of death.

Why it mattered

The case drew international attention to the danger ransomware poses to healthcare and showed how delays in patching can have serious real-world consequences.

Lessons for organisations

Prioritise patching of remote-access systems, maintain downtime procedures for critical services, and include clinical or operational continuity in incident response planning. Ensure that patching includes checking for signs of compromise, since attackers may have gained access before a fix was applied.

Sources: MIT Technology Review, Born’s Tech and Windows World

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights