CSIDB logo
Incident

Nukuʻalofa

Incident posture

Attack window
Jun 2025
Location
Tonga
Status
Unknown
CIA posture
Available to members
Updated
2026-10-04 00:45

Linked entities

Victim
Nukuʻalofa
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Pending
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The national health information system was encrypted by ransomware, prompting officials to shut it down and switch to manual record‑keeping while staff were unaware of the severity of the breach. Authorities disclosed that the attackers demanded a large payment and claimed they would not damage the data, though it remains uncertain whether any patient information was copied or leaked. An Australian cyber assistance team arrived to support recovery efforts, and government leaders urged residents to bring essential health records to hospitals to aid the temporary manual process. Officials noted that the incident marks the first ransomware event against the system since its introduction with international support, and they warned that the digital infrastructure needs stronger defenses against such threats.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Tonga’s National Health Information System (NHIS) suffered a ransomware breach this week, as announced by Dr ʻAna ʻAkauʻola in an evening statement. The breach came to light during a parliamentary debate on the MEIDECC budget when Deputy Prime Minister Dr Taniela Fusimalohi alerted members of parliament to the intrusion. Dr ʻAkauʻola said she had learned of the hack earlier in the week and immediately summoned system administrators, noting that the staff member managing the NHIS was unaware that it was a serious breach. She disclosed that the hackers had encrypted the NHIS and demanded payment while telling MPs that the hackers would not damage the information on the system.

Dr ʻAkauʻola also said she emailed Dr Fusimalohi upon learning of the breach, prompting him to engage the Australian High Commission, and Dr Fusimalohi confirmed that an Australian cyber team had arrived in Tonga to assist with resolution. She noted that this incident marks the first ransomware attack on the NHIS, which was introduced in 2019 with Asian Development Bank support to digitise health records and went live in 2021. Dr ʻAkauʻola warned that the attack illustrates one of the risks before full digitalisation, stating that patient data is currently inaccessible but that she cannot confirm whether confidential patient data has been compromised. Minister for Police Paula Piukala welcomed the shift to manual operations but criticised past governments for ignoring earlier warnings that Tonga’s digital infrastructure is not fully prepared for such threats.

He said the hackers are demanding millions of dollars and urged greater investment in IT infrastructure, while former Prime Minister Siaosi Sovaleni cautioned that the breach might have originated from a simple click on a malicious link, though it remains unclear if patient data was exfiltrated. Prime Minister ‘Aisake Eke affirmed that government efforts are underway and promised the public that updates will follow as the situation develops. In the meantime, residents have been urged via social media to bring essential records to hospitals to support manual record‑keeping, and further updates are expected as the Australian team works to restore full NHIS access.

Sources

Sources available to members: 1 source.

CSIDB