CSIDB logo
Incident

Listowel Hospital

Incident posture

Attack window
Sep 2019
Location
Canada
Status
Historical
CIA posture
Available to members
Updated
2026-01-09 23:08

Linked entities

Victim
Listowel Hospital
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Sep 2019
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack targeted the Listowel and Wingham hospital alliance, disrupting healthcare services and forcing temporary closures of oncology and diagnostic clinics. Non-emergency patients were advised to delay care as officials worked to restore systems, with no confirmed timeline for recovery. The Ontario Provincial Police cybercrimes unit launched an investigation amid broader concerns about ransomware targeting interconnected regional healthcare infrastructure. The incident occurred alongside attacks on multiple southwestern Ontario municipalities, highlighting coordinated threats to public sector networks. Hospital administrators implemented containment measures to prevent malware spread while managing operational disruptions.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

In late September 2019, a cyber-attack compromised the online system serving Listowel and Wingham hospitals in southwestern Ontario, forcing the temporary closure of oncology and diagnostic clinics. Hospital authorities directed non-emergency patients to return at later dates due to service disruptions. Karl Ellis, CEO of the Listowel Hospital Alliance, publicly acknowledged the incident but could not provide a restoration timeline for affected systems. The Ontario Provincial Police cybercrimes unit initiated an investigation into the attack. Officials implemented measures to contain the ransomware and prevent its spread to other networked components, though specific technical containment methods were not disclosed. Medical operations faced significant interruptions as hospital staff resorted to manual processes for critical functions. No patient data breaches or ransom demands were explicitly reported in connection with this hospital incident.

This attack occurred amid a wave of ransomware incidents across southwestern Ontario municipalities, following similar compromises in Stratford and Woodstock within the same month. Stratford had previously paid $75,000 to regain access to locked systems. Technical analyst Carmi Levy characterized the hospital attack as part of an escalating pattern targeting government entities, healthcare providers, and corporations. Levy emphasized the necessity for organizations to develop cyber incident response plans equivalent to natural disaster preparedness protocols. The interconnected nature of Ontario's healthcare networks raised concerns about potential cascading impacts across regional medical facilities. Hospital administrators maintained public communications regarding service restrictions while coordinating with law enforcement investigators throughout the disruption period.

Sources

Sources available to members: 1 source.

CSIDB