A ransomware attack on Düsseldorf University Hospital in Germany disrupted its IT systems and forced it to deregister from emergency care. German prosecutors opened an investigation after a critically ill patient, diverted to a hospital in Wuppertal, died.
What happened
- The attackers exploited a vulnerability in Citrix software for which a fix had been available since early 2020.
- The ransom note was reportedly addressed to the affiliated Heinrich Heine University; when police contacted the attackers, they provided a decryption key.
- The hospital postponed operations and outpatient treatment while systems were restored.
- Prosecutors later concluded the patient’s condition was so severe she would have died regardless, so the attack was not the cause of death.
Why it mattered
The case drew international attention to the danger ransomware poses to healthcare and showed how delays in patching can have serious real-world consequences.
Lessons for organisations
Prioritise patching of remote-access systems, maintain downtime procedures for critical services, and include clinical or operational continuity in incident response planning. Ensure that patching includes checking for signs of compromise, since attackers may have gained access before a fix was applied.
Sources: MIT Technology Review, Born’s Tech and Windows World
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.