Cyber Incident Victim: Rambam Medical Center
Date:
Feb 2024
Location:
Israel
Summary
An attempted cyberattack targeting Rambam Medical Center in Haifa was successfully identified and blocked through coordinated efforts involving the hospital, Israel's Health Ministry, and the National Cyber Directorate. The intrusion attempt caused no operational disruptions or damage to computer systems, with investigations ongoing into the incident. This event aligns with a pattern of similar cyber threats against Israeli healthcare facilities in recent times, where outcomes have varied between successful mitigations and operational compromises.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 4 motives | 2 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On February 5, 2024, Rambam Medical Center in Haifa reported successfully thwarting an attempted cyberattack targeting its computer systems. The incident occurred during the preceding night, with the hospital detecting and blocking the intrusion attempt before any operational disruption or damage to its systems occurred. The Health Ministry and Israel National Cyber Directorate collaborated with Rambam Medical Center in responding to the incident, confirming that hospital operations continued normally throughout and after the event. No patient data breaches or service interruptions were reported as a consequence of the attack. The coordinated response prevented any escalation, with authorities emphasizing that defensive measures functioned as intended.

The attempted breach remains under investigation by relevant Israeli cybersecurity and health authorities, though no specific threat actor or motive has been publicly identified. This incident aligns with a broader pattern of cyber targeting against Israeli healthcare infrastructure, including multiple successful and unsuccessful ransomware attacks on medical facilities in recent years. Historical precedents indicate such attacks often aim to disrupt critical services or extort payments, though Rambam’s case involved no ransom demands or data compromise. Hospital administrators maintained standard operations without activating emergency protocols, reflecting the containment’s effectiveness. Cybersecurity monitoring systems provided timely detection, enabling immediate countermeasures against the intrusion attempt.
