Yes, this is sad but true story... A patient at Düsseldorf University Hospital in Germany died after the hospital suffered a cyber attack.
According to Germany news publication RTL, the failure of IT systems caused by the cyberattack meant that the accident and emergency department at the hospital had to close, meaning the patient had to be transported to another hospital approximately 19 miles away, and subsequently died.
Düsseldorf University Hospital reported “far-reaching IT failures” on 10 September, which meant that the hospital was “only accessible to a very limited extent”. This was confirmed to be due to a cyber attack on 17 September after a hacker was able to exploit a weak point in “a commercial add-on software” which resulted in data being inaccessible. According to the hospital, the hacker has not demanded a randsom. Individual hospital systems are now gradually being put back into operation.
RTL has speculated that the attack was not intended for the hospital but for the University of Düsseldorf, with the perpetrators releasing the code to unlock the computer system after being contacted by the police.
German authorities are now investigating the patient’s death, and if they conclude that she died as a result of being transported to another hospital, the attack could be treated as a homicide.
The incident demonstrates the real-world, and sometimes tragic, impact increasingly sophisticated cyberattacks can have. “When cyberattacks impact critical systems, there can be real-world consequences” said Tim Erlin, VP at Tripwire.
“Ransomware doesn’t just suddenly appear on systems. It has to get there through exploited vulnerabilities, phishing, or other means. While we tend to focus on the ransomware itself, the best way to avoid becoming a victim is to prevent the infection in the first place. And the best way to prevent ransomware infections is to address the infection vectors by patching vulnerabilities, ensuring systems are configured securely, and preventing phishing.”