CSIDB logo
Incident

E.S.E Salud Yopal

Incident posture

Attack window
Jul 2024
Location
Colombia
Status
Historical
CIA posture
Available to members
Updated
2025-12-29 18:19

Linked entities

Victim
E.S.E Salud Yopal
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jul 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

E.S.E Salud Yopal experienced a cyber attack compromising its server system with malicious files, causing crashes and widespread service disruptions. Operational impacts included suspended services, delayed billing processes, and hindered patient care. The organization's systems team is actively investigating the incident's origins and intends to pursue judicial actions to identify responsible parties.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On July 3, 2024, E.S.E Salud Yopal publicly disclosed a cyber attack targeting its server infrastructure through an official Facebook announcement. The organization confirmed the presence of malicious files within its systems, which directly caused server crashes and widespread operational disruptions. These technical failures forced the suspension of critical healthcare services and created significant delays in billing processes across the facility. Patient care operations experienced interruptions as the information systems supporting clinical workflows became unavailable. The incident compromised the entire information service architecture, affecting multiple administrative and medical support functions simultaneously. Management characterized the event as sabotage but did not specify whether data theft or encryption occurred. No timeline was provided regarding the initial intrusion detection or the duration of system unavailability prior to the public statement.

The hospital's Systems team initiated forensic efforts to determine the origin and methodology of the attack while working to restore operational continuity. Administrative leadership under Manager Jhon Paulino Rojas Daza committed to pursuing legal action through judicial entities to identify and prosecute responsible threat actors. Public communications emphasized the ongoing nature of the technical response without detailing specific containment measures or recovery milestones. Service disruptions persisted at the time of the announcement, with no projected restoration timeline provided to stakeholders. The organization acknowledged the incident's impact on healthcare delivery while appealing for public understanding during the crisis management phase.

Sources

Sources available to members: 1 source.

CSIDB