Menu
Browse

Cyber Incident Victim: Saraburi Hospital

Date:

Sep 2020

Location:

Thailand

Summary

A ransomware attack compromised Saraburi Hospital's computer systems, disrupting operations. Although the incident involved ransomware encryption, no monetary demand was made by the attackers. The hospital advised patients to bring personal medical records and previous medication packaging for continuity of care during system outages, indicating significant disruptions to medical record access and prescription management capabilities. The director publicly confirmed the attack but provided no further details regarding recovery timelines or data compromise.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On September 5, 2020, Saraburi Hospital's director publicly confirmed a ransomware attack had compromised the hospital's computer systems. The attack disrupted normal operations, though no ransom demand was communicated to the hospital by the attackers. In response to the system compromise, the hospital advised patients visiting the facility to bring physical copies of their medical records and old medicine packaging to ensure continuity of care during the IT outage. This directive indicated critical patient data systems were rendered inaccessible, forcing reliance on manual documentation processes. The hospital did not disclose technical details about the ransomware variant, initial attack vector, or scope of encrypted systems beyond confirming the core computer network was affected. No patient data exfiltration or additional attacker objectives were reported.

Cyber Incident Image

The incident significantly impacted hospital workflows, necessitating temporary procedural adjustments to maintain basic services. The explicit instruction for patients to supply their own medical information suggested electronic health records were unavailable for retrieval or consultation by clinical staff. This operational disruption highlighted healthcare vulnerabilities to ransomware attacks targeting critical infrastructure. The absence of a ransom demand contrasted with typical ransomware incidents, leaving the attackers' motives unclear. Saraburi Hospital did not release information regarding system restoration timelines, incident detection methods, or containment measures undertaken during the response. The attack underscored the immediate consequences of cybersecurity incidents on healthcare delivery, particularly the reliance on manual workarounds when digital systems become unavailable.

Sources
Sources available to members
1 source