CSIDB logo
Incident

Ziekenhuis Oost-Limburg

Incident posture

Attack window
Feb 2021
Location
Belgium
Status
Historical
CIA posture
Available to members
Updated
2025-11-21 00:00

Linked entities

Victim
Ziekenhuis Oost-Limburg
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted Sacred Heart Hospital in Mol, where criminals infiltrated the IT system via email-delivered viruses, causing widespread system shutdowns. While no patient data was stolen or leaked, the disruption forced administrative operations to revert to paper-based processes. The incident did not compromise medical information or endanger patients, but significantly impaired the hospital's digital infrastructure.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On or around February 3, 2021, Sacred Heart Hospital in Mol, Belgium, experienced a cyber attack that disrupted its IT systems. The attackers introduced viruses into the hospital’s network, with initial investigations suggesting email as the likely intrusion vector. The malware successfully compromised multiple systems, forcing their shutdown to contain the spread and damage. Hospital administrators confirmed no patient medical data was exfiltrated during the incident, ruling out a data breach of sensitive health records. The attack primarily impacted administrative and operational systems, necessitating an immediate shift to paper-based processes for patient registration, scheduling, and record-keeping. Clinical care systems reportedly remained functional, allowing continued treatment without direct risk to patients. The hospital did not disclose whether ransomware was involved or whether the attackers made any financial or operational demands.

The hospital’s incident response team isolated affected systems to prevent further propagation of the malware. External cybersecurity experts were engaged to assist with forensic analysis and system restoration. Administrative staff reverted entirely to manual paper workflows, causing significant delays in non-clinical operations such as billing and appointment management. Hospital representatives emphasized that patient safety was never compromised despite the operational disruption. No evidence suggested collateral impact on partner healthcare facilities or regional medical networks. The investigation remained ongoing at the time of reporting, with no attribution publicly identified for the attack. Restoration timelines for full digital operations were not disclosed in initial statements.

Sources

Sources available to members: 1 source.

CSIDB