CSIDB logo
Incident

Brno University Hospital

Incident posture

Attack window
Mar 2020
Location
Czechia
Status
Historical
CIA posture
Available to members
Updated
2025-10-31 00:00

Linked entities

Victim
Brno University Hospital
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

Brno University Hospital, a critical COVID-19 testing facility in the Czech Republic, suffered a severe cyberattack that forced the shutdown of its IT network across two branches, disrupting operations during a pandemic outbreak. The incident led to postponed urgent surgeries, diversion of acute patients to another hospital, and repeated internal warnings demanding immediate computer shutdowns. National cybersecurity authorities, law enforcement, and hospital IT personnel collaborated on recovery efforts, highlighting the vulnerability of healthcare infrastructure to attacks exploiting crisis conditions.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On March 13, 2020, Brno University Hospital, one of the Czech Republic's largest COVID-19 testing laboratories, suffered a severe cyberattack during a local coronavirus outbreak. The hospital administration did not disclose technical details of the breach but classified the incident as critical enough to disrupt core medical operations. Officials canceled urgent surgical interventions starting at 8 a.m. and diverted new acute patients to nearby St. Anne's University Hospital. The hospital proactively shut down its entire IT network to contain the attack, affecting operations across two separate branches. Staff received repeated instructions through public address systems to immediately power down computers, with security alerts broadcast every 30 minutes citing "cybernetic security" threats. These network disruptions forced the postponement of scheduled medical procedures and created operational challenges for patient triage during the emerging public health crisis.

The hospital's IT personnel collaborated with the Czech National Cyber Security Center (NCSC) and law enforcement agencies to restore systems. As a primary COVID-19 testing facility in the early stages of the pandemic, the attack compromised Brno's capacity to process tests amid rising infection rates. Security experts observing the incident noted that threat actors frequently exploit crisis situations, targeting healthcare organizations when staff are overwhelmed by emergency response demands. While no data theft or ransomware demands were confirmed in available reports, the operational paralysis demonstrated significant vulnerabilities in critical healthcare infrastructure during global emergencies. The coordinated response between national cybersecurity authorities and hospital technicians focused on rebuilding secure systems while maintaining minimal essential services through manual protocols.

Sources

Sources available to members: 1 source.

CSIDB