Centre Hospitalier de la Polynésie française
Incident posture
Linked entities
- Victim
- Centre Hospitalier de la Polynésie française
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A cyberattack targeted the Centre Hospitalier de la Polynésie française, triggering a security alert after numerous external connection attempts potentially linked to a global campaign. The hospital immediately activated its protection protocols and disconnected its information system from the internet to neutralize ongoing offensive actions and assess whether any intrusion or malicious software had compromised the network. Despite this precautionary isolation, the facility reported that medical, technical, and administrative data remained intact and accessible, with software functioning normally. Patient care was not degraded, though external communications were temporarily limited. The institution committed to restoring full communication capacity as quickly as possible while safeguarding sensitive data.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Monday evening, February 10, 2025, the Centre Hospitalier de la Polynésie française (CHPF) detected a security alert concerning its information system. According to a communiqué issued by the establishment, the alert was triggered by "numerous connection attempts from external internet sites" that could be "linked to a worldwide campaign of this type currently underway." The wording used by the hospital suggested that the activity resembled patterns associated with a global wave of cyberattacks targeting the healthcare sector, which had already been documented in other regions. The triggering of the alert marked the formal beginning of the incident from the hospital's perspective, even though the full nature and intent of the external connection attempts had not yet been confirmed at that stage.
In response to the detected activity, the CHPF immediately activated its pre-established protection measures. The hospital's statement emphasized that its software remained functional and that medical, technical, and administrative data had not been compromised, remaining fully available to staff. Despite this initial reassurance regarding the integrity of internal data, the establishment chose, on the advice of its cybersecurity service providers, to temporarily disconnect its information system from the Internet. This precautionary isolation, described as a "quarantine" measure, was intended to neutralize any ongoing offensive actions and to allow for a detailed analysis of the situation. The specific goal of this analysis was to confirm that no intrusion had actually taken place and, in the event that one had, to determine whether any malicious software had been deposited within the information system. By cutting external connectivity, the hospital sought to prevent any potential exfiltration or further unauthorized access while preserving internal operations. The decision to disconnect from the Internet, while disruptive to external communications, was presented as a necessary step to validate the security of the environment.
The immediate consequence of the disconnection was a complication in exchanges with external interlocutors, including partner organizations, regulatory bodies, and other entities that typically interact with the hospital's systems. However, the CHPF explicitly stated that the daily care of patients was not degraded, indicating that clinical activities continued to function using internal procedures and resources. The hospital also expressed its commitment to quickly restoring full communication capabilities while ensuring the security of patients' medical and administrative data. At the time of the report, no ransomware group, hacktivist collective, or other threat actor had been publicly identified in connection with the incident, and no data theft, encryption, or service outage affecting patient care had been confirmed. The hospital framed the event as a precautionary response to a potential threat, with ongoing verification steps being carried out by its cybersecurity teams. The broader context noted in coverage of the incident pointed to a report published by the French National Cybersecurity Agency (ANSSI) in November of the previous year, which had highlighted the persistent and concerning risk of data theft within the healthcare sector, underscoring the relevance of the protective measures taken by the CHPF.
Sources
Sources available to members: 1 source.