CSIDB logo
Incident

Chansn Hospital

Incident posture

Attack window
Apr 2025
Location
Taiwan
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 11:16

Linked entities

Victim
Chansn Hospital
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Apr 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A hospital in Taoyuan's Zhongli District was recently hit by a ransomware attack that disrupted medical services and potentially compromised over 80,000 patient records. The facility received a ransom email demanding payment and signed by international hackers, prompting immediate emergency protocols including disconnection of internal and external networks, a full systems scan, and a police report. Online registration remained unavailable for several days as staff worked to reinstall antivirus software and restore IT infrastructure, though patients could still register by phone or in person. The attack severely impacted core operations, including appointment booking, new patient intake, and prescription issuance. Local authorities and the Ministry of Health and Welfare are monitoring the situation, with a formal investigation underway to determine the extent of any data breach.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On April 14, 2025, Chansn Hospital, a medical facility located in the Zhongli District of Taoyuan, Taiwan, received a ransom email that marked the beginning of a significant ransomware incident. The message, which was sent to the hospital's administration, contained ransom demands and was signed by what authorities have identified as international hackers. Upon discovery of the email, the hospital initiated its emergency response protocols. On April 15, the day after the ransom demand was received, the hospital filed a formal police report and took immediate steps to contain the incident. These steps included disconnecting both its internal and external networks to prevent further spread or unauthorized access, and commissioning a comprehensive systems scan to assess the extent of the compromise and identify any malicious presence within the IT infrastructure. The decision to sever network connectivity reflected the severity of the situation and the hospital's commitment to limiting potential damage to patient data and operational systems.

The Taoyuan Department of Public Health confirmed that the ransom demands were transmitted via email and were attributed to overseas actors, prompting the Zhongli Precinct to launch a formal investigation under computer crime statutes. Police have indicated that the involvement of international hackers is suspected, and the case is being treated as a serious cybersecurity offense. As of April 19, 2025, the hospital reported that its online registration system remained unavailable, indicating that the restoration efforts were still ongoing. Hospital staff noted that while digital infrastructure was still being repaired, patients were able to register for appointments by phone or in person, ensuring that some level of medical service continuity was maintained despite the disruption. The attack specifically impacted several critical hospital functions, including appointment booking, new patient intake procedures, and the issuance of prescriptions, all of which relied on the compromised digital systems. Chansn Hospital, which was formerly part of the Hsinchu An Shen Clinic system, serves as a major local healthcare facility and provides long-term care services to up to 10,000 patients, raising concerns about the potential scale of the data exposure.

In response to the incident, the hospital has undertaken efforts to reinstall antivirus software across its systems and to restore its broader IT infrastructure from backups or clean installations. These remediation activities are essential for ensuring that the hospital's digital environment is secure before normal operations can fully resume. Should evidence emerge confirming that patient data was actually accessed or exfiltrated during the attack, the hospital is obligated to report the data leak in accordance with official ransomware response guidelines established by Taiwanese authorities. The Ministry of Health and Welfare has stated that it is actively monitoring the incident and its potential implications for the healthcare sector more broadly. This cyberattack on Chansn Hospital follows similar incidents at other Taiwanese medical institutions, including Mackay Memorial Hospital and Changhua Christian Hospital, both of which have previously experienced cyberattacks and serve as precedents for how such incidents are handled within the country's healthcare cybersecurity framework.

The potential compromise of over 80,000 patient records represents a significant concern given the hospital's role in providing long-term care services to a large patient population in the region. The combination of immediate network disconnection, engagement of law enforcement, and collaboration with public health authorities demonstrates a coordinated response to the ransomware threat. As the investigation continues and system restoration efforts progress, the hospital remains focused on returning its digital services to full operational capacity while maintaining alternative registration methods to accommodate patient needs during the recovery period.

Sources

Sources available to members: 1 source.

CSIDB