A BackMyData ransomware attack disrupted Romania's healthcare sector after attackers breached Bucharest-based software firm RSC and compromised its widely used Hippocrates hospital management platform. Romanian authorities said more than 100 hospitals were told to disconnect from the internet to contain the spread, while 26 hospitals were confirmed as directly infected. Because Hippocrates supported admissions, lab tests, radiology, medicines, supplies, payroll, pharmacy logistics, and test results, clinicians and administrators were forced to abandon digital systems and return to pen-and-paper and other offline workflows.
The attackers encrypted files and demanded roughly €160,000 in Bitcoin, but Romanian officials instructed hospitals not to negotiate or pay. Most affected systems were restored within about five days using secure backups, though some data was permanently lost. The response by hospital staff, IT teams, and Romania’s national cyber authorities has since been cited as a notable example of healthcare incident response, emphasizing the value of network isolation, resilient backups, crisis communications, and rehearsed continuity plans.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Romanian authorities instructed affected hospitals not to negotiate with or pay the attackers during the incident response. The guidance accompanied broader containment and recovery efforts across the healthcare sector.
Investigators later determined that 26 hospitals were directly infected with BackMyData ransomware during the Romania healthcare-sector incident. The malware encrypted files and the attackers demanded €160,000 in Bitcoin.
Most affected systems were restored within five days using secure backups, though some data was permanently lost. The recovery ended several days of paper-based operations at impacted hospitals.
During the February 2024 incident, Romania’s National Directorate for Cyber Security ordered more than 100 hospitals to disconnect from the internet to limit the spread of the attack. The move forced medical staff to switch to paper-based and offline workflows while investigators worked on containment.
On 2024-02-10, attackers breached Bucharest-based software firm RSC and compromised its Hippocrates hospital management system, triggering a ransomware incident that disrupted hospitals across Romania. The attackers deployed the BackMyData ransomware strain, encrypting files and demanding payment in bitcoin.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cysecurity.news
Open sourcebbc.co.uk
Open sourcebbc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.