CSIDB logo
Incident

Advania AB

Incident posture

Attack window
Feb 2024
Location
Sweden
Status
Historical
CIA posture
Available to members
Updated
2026-01-03 20:14

Linked entities

Victim
Advania AB
Threat actors
0 actors
Sources
2 sources

Timeline

Occurred
Feb 2024
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeting Advania's customer environment prompted the isolation of affected systems, impacting approximately 60 clients. The intrusion, confirmed as external in origin, disrupted critical services for multiple healthcare providers in Västra Götaland, including the inability to access medical records, process lab samples, or accept patients, forcing reliance on paper prescriptions. While no ransomware was detected, the investigation remains ongoing to determine the full scope and restore services. Other private healthcare facilities sharing the same IT supplier experienced similar operational outages.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 6, 2024, IT provider Advania detected an anomaly in a segment of its customer environment during Tuesday afternoon operations, prompting immediate isolation of the affected systems for investigation. The company confirmed the incident involved unauthorized access by an external actor but found no evidence of malicious code deployment, such as ransomware, within the compromised environment. Approximately 60 customers experienced service disruptions as a direct result of the isolation measures. Advania prioritized determining the incident's scope and root cause to facilitate restoration of customer environments, maintaining communication with impacted clients throughout the process. Operational isolation of the customer environment remained in effect during the ongoing investigation to safeguard both Advania and its clients.

The cyberattack caused significant operational disruptions across multiple sectors, particularly affecting healthcare providers in Västra Götaland region. Herkules vårdcentral in Borås reported complete inability to access patient journals, process lab samples, or accept new patients, forcing staff to issue paper prescriptions exclusively. Per Svensson, the facility's operations manager, confirmed neighboring private healthcare centers sharing the same IT provider faced identical service outages. Advania's public statement acknowledged the incident's severity but provided no technical specifics regarding intrusion methods, data compromise, or expected recovery timelines beyond its commitment to resolution. Investigation and restoration efforts continued without further public elaboration of forensic findings or attacker attribution as of the latest available reports.

Sources

Sources available to members: 2 sources.

CSIDB