CSIDB logo
Incident

Marista Group

Incident posture

Attack window
Mar 2022
Location
Brazil
Status
Historical
CIA posture
Available to members
Updated
2026-03-09 17:28

Linked entities

Victim
Marista Group
Threat actors
2 actors
Sources
2 sources

Timeline

Occurred
Mar 2022
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted the Marista Group, disrupting operational systems across affiliated hospitals and a university, including Hospital Cajuru and Marcelino Champagnat. The attack forced systems offline for multiple days, requiring manual handling of medical records and medication administration while patient care continued unaffected. Staff operated without network access, and public-facing websites displayed maintenance notifications during the outage.

Motives

Detailed motive labels are available to members.

5 motives

TTPs

Detailed technique labels are available to members.

7 techniques

Description

On or around March 13, 2022, the Marista Group's operational systems suffered a cyberattack that disrupted services across multiple healthcare and educational institutions under its management. The attack forced Hospital Cajuru, Marcelino Champagnat Hospital, and Pontifícia Universidade Católica do Paraná (PUCPR) to operate without functional IT systems for at least three days. Employees reported being effectively "blind" due to the sustained network and system outages, which rendered digital infrastructure inoperable. Public-facing websites displayed maintenance notifications instead of normal interfaces, indicating deliberate takedowns or system isolation. The prolonged disruption suggests attackers compromised critical backend systems rather than conducting superficial website defacements.

The Marista Group confirmed through official statements that patient care continued despite operational instability, with medical teams reverting to manual documentation processes. Staff maintained physical medical records for patient histories and medication administration, demonstrating established contingency protocols for critical care continuity. No evidence suggests treatment delays or compromised medication safety resulted from the attack. The organization did not disclose whether data theft occurred or identify specific threat actors, focusing communications on service continuity measures. System restoration timelines remained unspecified in available reports, though the three-day outage window indicates significant recovery challenges. The incident's scope impacted both healthcare delivery and academic operations at PUCPR, highlighting cross-sector vulnerabilities within the group's integrated infrastructure.

Sources

Sources available to members: 2 sources.

CSIDB