CSIDB logo
Incident

Cistec

Incident posture

Attack window
Feb 2025
Location
Switzerland
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-02 13:48

Linked entities

Victim
Cistec
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Undetermined
Disclosed
Feb 2025
Resolved
Pending

Summary

The Swiss software provider Cistec, which develops the Kisim clinical information system used in hospitals, suffered a ransomware attack during the night, prompting the company to immediately shut down all of its systems to prevent further spread. The incident affected services connected to Active Directory, including Exchange, and Cistec engaged external cybersecurity specialists while notifying the Zurich Cantonal Police cybercrime division, the Federal Data Protection Commissioner (Edöb), and the Government Computer Emergency Response Team (GovCert). Analyses conducted by the specialists and GovCert determined that no customer systems, including Kisim, were impacted by the attack. The company also stated that because it does not store patient data from customer systems on its own infrastructure, the encryption or theft of patient data could be ruled out. Cistec is currently rebuilding its internal systems in a new, secure IT environment and bringing them back online in stages.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In the night of February 12, 2025, the Swiss software provider Cistec became the victim of a ransomware attack, an incident the company itself confirmed when approached for comment. Cistec is known as the manufacturer of the hospital information system Kisim, which is used by clinical institutions in Switzerland. According to the company's own statement, the ransomware struck during the overnight hours and targeted services that were connected to Cistec's Active Directory environment. Among the affected services was Exchange, the widely used messaging platform that relies on directory integration for authentication and access control. The nature of the attack indicated that the attackers had gained sufficient foothold within the network to reach directory-tied infrastructure, allowing them to encrypt or otherwise compromise systems tied to those services.

Upon discovering the intrusion, Cistec responded by immediately shutting down all of its systems in order to prevent the ransomware from spreading further into additional parts of the environment. This decision to take the entire infrastructure offline, while disruptive to internal operations, was intended as a containment measure to limit the blast radius of the attack. Following the shutdown, Cistec engaged external cybersecurity specialists to assist with the investigation and remediation. Together with these specialists, the company implemented further technical measures to assess the scope of the compromise, secure remaining systems, and begin planning the recovery process. The incident was also reported to several official bodies, including the Cybercrime Division of the Zurich Cantonal Police, the Federal Data Protection and Information Commissioner (Edöb), and the Government Computer Emergency Response Team (GovCert) operating under the Federal Office for Cyber Security (Bacs).

According to analyses carried out by the engaged cybersecurity specialists and GovCert, no customer systems were affected by the attack at the time of the company's statement to inside-it.ch. Cistec emphasized that this assessment specifically extended to Kisim, its hospital information system product. The company further clarified that no patient data from customer systems is stored within Cistec itself, a structural separation that allowed the provider to state with confidence that patient data could not have been encrypted or exfiltrated as part of the incident. This separation between Cistec's internal environment and the customer-deployed systems was a key factor in containing the operational and reputational impact of the breach, as hospitals relying on Kisim could continue to operate their on-premises deployments without interruption.

In the aftermath of the attack, Cistec shifted its focus to the reconstruction of its internal IT environment. The company announced that it had rebuilt its internal systems within a new, secure IT environment and was in the process of bringing these systems back online step by step. This staged recovery approach was designed to verify the integrity of each component before reconnecting it to operational use, reducing the risk of reintroducing compromised elements into the rebuilt environment. The decision to construct a new environment rather than simply restoring from backups reflected a deliberate effort to ensure that latent threats or attacker footholds would not persist once systems were brought back online.

The Cistec incident occurred against a broader backdrop of scrutiny concerning the security of hospital information systems used in Swiss healthcare facilities. Independently of the ransomware attack, the Network Testing Center (NTC) had recently evaluated the systems offered by Cistec, Epic, and Ines, and identified vulnerabilities in each. Cistec addressed these findings by acknowledging a single critical vulnerability in its system, but noted that exploitation of this flaw required an attacker to already possess full administrative rights within the internal hospital network. According to the company, this vulnerability had since been remediated.

Sources

Sources available to members: 1 source.

CSIDB