Romanian Hospital Ransomware Attack via Medical Software Supply Chain (Feb 2024)
Retrospective case study of the February 2024 'BackMyData' ransomware attack that infected 26 Romanian hospitals via a supply-chain compromise of medical software vendor RSC (Hippocrates system). Over 100 hospitals were proactively disconnected and ran on pen-and-paper for up to five days. A €160,000 ransom was refused; no patient deaths or serious harm were reported. Attribution to a specific gang remains unconfirmed by Romanian police, though a related gang's site was taken down and four Russians were arrested abroad. Romanian DNSC coordinated the national response. No insurance claims, final financial losses, or market-moving pricing actions have been disclosed.
AI-generated from linked source reports. See our correction policy.
Impact verdict
Low impact. Loss pathway remains bounded: ransom was refused; disruption was contained within approximately five days; no patient deaths or serious harm were reported; no insured-loss estimate, no named commercial insured, and no evidence of market-moving pricing, capacity, or reinsurance action. The event is material as a healthcare cyber supply-chain case study, not as a quantified London Market loss. Material constraints persist: no insurance claims data, no police-confirmed attribution, and no final financial loss figures.
View assessment methodologyPremium discovery tier
Unlock analyst briefs, intelligence depth, and the revision timeline
Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.
Start two-week trialAffected countries
Lloyd's classifications
Tracking this kind of risk? Get an email when Cyber events escalate.
Get alerts