BUCHAREST — More than 100 hospitals in Romania were ordered to disconnect from the internet in February 2024 following a ransomware attack. Dan Cimpean, head of Romania's national cyber-security center (DNSC), issued the order.

The cyber-attack targeted a medical software system called Hippocrates, produced by the Bucharest-based firm RSC. The ransomware strain used in the attack was identified as BackMyData. Staff at Pitești children's hospital were the first to notice errors on Sunday morning when the attack began.

Cyber-investigators determined that 26 hospitals had been infected with the BackMyData ransomware. The attackers demanded a ransom of €160,000 in bitcoin. Romanian officials made a national decision not to pay the ransom.

Most hospitals were back online and operating close to normal within five days of the attack. There were no reported deaths or serious harm to patients during the outage. Public messaging during the attack urged patients to avoid hospitals unless necessary.

Oana Goidescu, a surgeon at Buzău Hospital, described the experience. "It was quite an unpleasant experience, because an IT record is not just a list of patients," Goidescu said. "For each patient, we request lab tests, radiology, medicines and supplies. All of that was gone."

Dan Cimpean, head of Romania's Cyber-Security Directorate, commented on the broader implications. "The more technology you have, the more digitised you are, the greater the risk," Cimpean said. Alina Bîzgă, a cyber-security analyst with Bitdefender, explained why hospitals are often targeted. "Hospitals handle critical services, and the criminals think that the more disruption that can be caused, the more likely they are to get paid a ransom," Bîzgă said.