Menu
Browse

Cyber Incident Victim: Brno University Hospital

Date:

Mar 2020

Location:

Czechia

Summary

Brno University Hospital, a critical COVID-19 testing facility in the Czech Republic, suffered a severe cyberattack that forced the shutdown of its IT network across two branches, disrupting operations during a pandemic outbreak. The incident led to postponed urgent surgeries, diversion of acute patients to another hospital, and repeated internal warnings demanding immediate computer shutdowns. National cybersecurity authorities, law enforcement, and hospital IT personnel collaborated on recovery efforts, highlighting the vulnerability of healthcare infrastructure to attacks exploiting crisis conditions.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On March 13, 2020, Brno University Hospital, one of the Czech Republic's largest COVID-19 testing laboratories, suffered a severe cyberattack during a local coronavirus outbreak. The hospital administration did not disclose technical details of the breach but classified the incident as critical enough to disrupt core medical operations. Officials canceled urgent surgical interventions starting at 8 a.m. and diverted new acute patients to nearby St. Anne's University Hospital. The hospital proactively shut down its entire IT network to contain the attack, affecting operations across two separate branches. Staff received repeated instructions through public address systems to immediately power down computers, with security alerts broadcast every 30 minutes citing "cybernetic security" threats. These network disruptions forced the postponement of scheduled medical procedures and created operational challenges for patient triage during the emerging public health crisis.

Cyber Incident Image

The hospital's IT personnel collaborated with the Czech National Cyber Security Center (NCSC) and law enforcement agencies to restore systems. As a primary COVID-19 testing facility in the early stages of the pandemic, the attack compromised Brno's capacity to process tests amid rising infection rates. Security experts observing the incident noted that threat actors frequently exploit crisis situations, targeting healthcare organizations when staff are overwhelmed by emergency response demands. While no data theft or ransomware demands were confirmed in available reports, the operational paralysis demonstrated significant vulnerabilities in critical healthcare infrastructure during global emergencies. The coordinated response between national cybersecurity authorities and hospital technicians focused on rebuilding secure systems while maintaining minimal essential services through manual protocols.

Sources
Sources available to members
1 source