Instituto de Salud Pública de Chile
Incident posture
Linked entities
- Victim
- Instituto de Salud Pública de Chile
- Threat actors
- 0 actors
- Sources
- 2 sources
Timeline
Summary
On a Friday in late June, the Instituto de Salud Pública de Chile suffered a cyberattack that forced the organization to disable its servers and take multiple digital platforms offline to contain the threat. Although the institute reported no concrete evidence of data exfiltration, the disruption halted services tied to sanitary certificates required by customs, creating a logistical breakdown for imports of medicines, cosmetics, and medical devices and prompting exceptional authorization measures from customs authorities. Internal communications, telephone services, and email remained operational, while urgent procedures such as sample reception, transplants, batch controls, and registrations were prioritized. The agency immediately engaged Chile's National Cybersecurity Agency (ANCI), filed a formal complaint with the Public Ministry, and worked with the Investigations Police and external experts to investigate the incident and restore systems. A new institutional website was launched to keep the public informed while recovery efforts continue.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On Friday, June 27, 2025, the Instituto de Salud Pública de Chile (ISPCH) detected a computer security incident that triggered the immediate activation of its incident response protocol. The institution's information security team mobilized along with external experts to contain the threat and protect the organization's infrastructure and information. On the same day, the ISPCH contacted the Agencia Nacional de Ciberseguridad (ANCI), whose professionals arrived at the Institute to jointly define containment measures. Also on June 27, a formal complaint was filed with the Ministerio Público to initiate an investigation, and the Policía de Investigaciones (PDI) visited the ISPCH to begin its own proceedings. Together with ANCI, the Institute initiated a thorough analysis of the incident and a preventive review of its servers. At the time of the initial reporting, no concrete evidence of any data leak or information exposure had been identified. Despite the severity of the event, the institution's telephone network and institutional email were not affected, which allowed continued communication with users and other state agencies, helping to prevent any impact on public health functions. Following detection, several servers were deactivated as an extreme measure to prevent potential data exposure, and the organization maintained minimal operations through alternative channels such as physical reception of samples and urgent care.
In the days and weeks that followed the incident, the ISPCH continued to coordinate with national authorities and external experts to advance system recovery. Although the institution stated that there was no sensitive information leak, the attack did stop the procedures related to sanitary certificates required by Aduanas, generating a critical logistical break for products such as medications, cosmetics, and medical devices. To prevent a broader paralysis, Aduanas implemented exceptional resolutions including the use of authorizations without the Certificado de Destinación Aduanera, the inclusion of a specific gloss in declarations, and coordination with importers to regularize procedures once the contingency was concluded. On July 10, a meeting was held with representatives of the industry regulated by the ISPCH and members of the Consejo de la Sociedad Civil, with periodic communications planned to continue. Internally, the institution instructed the prioritization of urgent procedures such as those related to the reception of samples, transplants, batch controls, registries, and exemption from quality control, among others. The incident also generated a national political alert, with parliamentarians qualifying the event as a "red alert" and demanding clarity regarding possible data breaches and a review of the ISPCH's cybersecurity procedures, noting that the lack of knowledge about the attack's scope was particularly serious given the institution's role as a national regulatory body.
As part of the recovery efforts, the ISPCH migrated its institutional website to a new address, www.ispch.gob.cl, where the functionalities of the previous page were made available. The Sistema Integral de Información y Atención Ciudadana (SIAC-OIRS) platform was also fully enabled, allowing users to request information about the status of their procedures, consultations, claims, and other matters through the "Estado de mi Trámite" option in the SIAC form on the institutional website. Systems that were still undergoing recovery were identified with a "próximamente" (soon) message. On July 14, 2025, the ISPCH issued Instructivo N°1 detailing the contingency status and providing guidance to regulated parties on how to proceed during the event. The document outlined that the electronic prestations available at the ISP were being continuously updated and indicated the procedures for urgent matters that required attention. The instructivo committed the institution to ongoing updates as recovery of the systems progressed, reflecting an active and structured response to restore operational continuity while maintaining essential public health functions and supporting the continuity of foreign trade operations that had been disrupted by the cyberattack.
Sources
Sources available to members: 2 sources.