Menu
Browse

Cyber Incident Victim: Ziv Medical Center

Date:

Dec 2023

Location:

Israel

Summary

A cyberattack on Ziv Medical Center allegedly resulted in the theft of over 500 gigabytes of data, including hundreds of thousands of patient medical records, with claims by Iran-linked hackers that 100,000 documents pertained to IDF personnel. The attackers shared screenshots of medical records and hinted at further actions, prompting the hospital and authorities to acknowledge indications of leaked information and impose a gag order alongside criminal prohibitions on using or distributing stolen data. The medical center temporarily restricted external emails and disconnected certain computer services as a precaution, while Israeli cybersecurity and health agencies confirmed the incident was contained without operational disruption.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

On December 1, 2023, Iran-linked hackers claimed responsibility for a cyberattack on Ziv Medical Center in Safed, Israel, alleging the theft of over 500 gigabytes of sensitive data. The stolen information reportedly included hundreds of thousands of patient records, with the attackers specifying that 100,000 documents pertained to Israeli Defense Forces personnel. This marked the third cyberattack targeting the hospital within a four-month period. The Health Ministry and Israel National Cyber Directorate confirmed detecting a suspected cyber intrusion in the hospital's computer systems, stating the incident was promptly identified and contained without disrupting medical operations. The hacker group publicized their claims on Telegram, sharing screenshots of medical documents dated to 2022 as evidence and threatening an unspecified "another surprise" in future communications.

Cyber Incident Image

In response to the breach, Ziv Medical Center and the Justice Ministry's Privacy Protection Authority issued a joint statement acknowledging indications of information leakage from hospital systems. Authorities imposed a gag order to remove compromised content from public platforms and enacted criminal prohibitions against using, transferring, or distributing leaked personal data, with warnings of legal action against violators. The hospital implemented temporary security measures including restrictions on external email communications and disconnection of select computer services. Public advisories urged vigilance against suspicious messages purporting to originate from the hospital, emphasizing avoidance of unverified links or attachments. No operational disruptions to medical services were reported following containment efforts.

Sources
Sources available to members
1 source