CSIDB logo
Incident

Carol Davila Hospital

Incident posture

Attack window
Feb 2024
Location
Romania
Status
Resolved
CIA posture
Available to members
Updated
2026-09-10 04:26

Linked entities

Victim
Carol Davila Hospital
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2024
Discovered
Undetermined
Disclosed
Undetermined
Resolved
Feb 2024

Summary

A ransomware attack exploiting the Hippocrates medical software infected numerous Romanian hospitals, forcing them to disconnect from the internet and revert to paper‑based processes. At Carol Davila Hospital staff created offline workflows, using paper records and Excel to continue patient care while IT teams worked with the software vendor to isolate the BackMyData ransomware and restore systems from backups. Within days most facilities were back online, though the paper‑based data entry caused delays and some information loss, with no reported fatalities or serious patient harm.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The cyber‑attack on Romania’s hospitals began on 10 February 2024 when threat actors compromised the Bucharest‑based software firm RSC and inserted the ransomware strain BackMyData into the widely used Hippocrates medical system. The first signs of infection appeared at Pitești children’s hospital on Sunday morning, the day after the initial compromise, and by dawn on Monday many other hospitals reported that the Hippocrates platform was unavailable. In response, the national cyber‑security centre (DNSC) ordered more than 100 hospitals, including Carol Davila Hospital in Bucharest, to disconnect from the internet immediately to halt the spread of the ransomware. This forced medical staff to revert to pen‑and‑paper processes; at Carol Davila Hospital, Vlad Paic described how the team requested laboratory results on paper, used Excel and other offline tools to register patients, and improvised workarounds to maintain care while IT teams worked to assess the infection. The disruption affected admissions, payroll, pharmacy logistics, test results and other hospital functions that normally relied on the Hippocrates system.

Over the following days, cyber‑investigators collaborated with the Hippocrates developer to determine the scope of the breach, identifying that 26 hospitals had been infected with BackMyData. Uninfected facilities were gradually brought back online the next day with additional protective measures, while IT teams at affected hospitals restored systems from recent backups. Within five days of the initial disconnect order, most hospitals had resumed operations close to normal, with no reported deaths or serious harm to patients. However, re‑entering the data recorded on paper during the outage took weeks, and some information was permanently lost. Police have not disclosed details of their investigation into the attackers, though the article notes that a ransomware gang linked to BackMyData had its website taken down in an international operation the previous year, resulting in the arrest of four Russians outside their country. The DNSC highlighted that the incident demonstrated how reliance on digital health infrastructure increases risk, but also showed that rapid isolation and backup‑driven recovery can limit patient harm.

Sources

Sources available to members: 1 source.

CSIDB