CSIDB logo
Incident

Hospi Grand Ouest

Incident posture

Attack window
Oct 2024
Location
France
Status
Unknown
CIA posture
Available to members
Updated
2025-12-27 00:00

Linked entities

Victim
Hospi Grand Ouest
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted the Hospi Grand Ouest healthcare group, impacting one of its nine facilities—the mutualist clinic La Sagesse in Rennes—while other establishments, including the Jules-Verne and Estuaire clinics, remained unaffected. The incident disrupted operations at the compromised facility, prompting containment measures by management, who confirmed the attack was isolated to a single site by Saturday evening. No broader service interruptions across the group's network were reported.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

A cyberattack targeted the Hospi Grand Ouest (HGO) healthcare group on Thursday, October 3, 2024, impacting one of its nine facilities. The attack initially affected La Sagesse mutualist clinic in Rennes, Ille-et-Vilaine, with HGO management confirming no immediate impact on other group establishments. By Saturday evening, October 5, HGO officials publicly stated the Jules-Verne clinic in Nantes and Estuaire clinic in Saint-Nazaire – both in Loire-Atlantique – remained unaffected. Management emphasized containment efforts had restricted operational disruption to La Sagesse clinic alone, though technical details regarding the attack vector or compromised systems weren't disclosed. No patient data breaches or service interruptions at non-impacted facilities were reported in available information.

HGO's crisis communication focused on clarifying operational status across its network as of October 5. The group reiterated that eight of nine facilities maintained normal operations despite the ongoing incident at La Sagesse. Management did not specify whether emergency protocols were activated or external cybersecurity agencies involved. No ransomware groups claimed responsibility, and the article contained no information about data exfiltration, financial demands, or recovery timelines. The attack's discovery timeline remained undefined beyond the initial October 3 reporting date. Impacts were geographically confined to Rennes, with no observed cascading effects on partner institutions or regional healthcare systems according to available reports.

Sources

Sources available to members: 1 source.

CSIDB