Menu
Browse

Cyber Incident Victim: ASST-Rhodense

Date:

Jun 2024

Location:

Italy

Summary

A cyberattack disrupted the information systems of ASST-Rhodense, with attackers demanding a ransom. The incident prompted involvement from the Lombardy Region, which activated its cybersecurity task force and engaged regional agency Aria. The National Cybersecurity Agency was alerted and deployed a team to assist recovery efforts. The affected hospitals serve a population of approximately 483,000 residents. While the attack's origin remains unspecified, authorities have not confirmed any link to a separate ransomware incident targeting Synlab Italia in late May.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actors Type Location
0 actors Available to members Available to members

Description

On June 6, 2024, ASST Rhodense, a healthcare organization in Lombardy, Italy, experienced a disruptive cyberattack that began during the previous night. The attack caused significant operational disruptions, rendering the organization’s information systems inoperable ("sistemi informatici in tilt"). The perpetrators issued a ransom demand to the healthcare provider, though the specific demands or payment mechanisms were not disclosed. The incident exclusively impacted ASST Rhodense’s infrastructure at the time of reporting, with no confirmed collateral damage to external regional systems. Hospitals under ASST Rhodense’s jurisdiction serve a population of approximately 483,000 residents across their operational territory, amplifying concerns about potential disruptions to patient care and administrative functions. No further technical specifics regarding the attack vector, malware type, or data compromise were verified in the available reporting.

Cyber Incident Image

In response, the Lombardy Region activated its regional cybersecurity task force and engaged Aria, an entity referenced in context but not explicitly defined in the source material. Concurrently, Italy’s National Cybersecurity Agency was alerted and deployed a specialized team to assist ASST Rhodense with recovery efforts. Investigators had not yet determined whether the threat actors responsible for this attack were connected to a late May 2024 ransomware incident targeting Synlab Italia, a separate healthcare diagnostics provider. The incident remained under active investigation with no public confirmation of system restoration timelines or whether ransom negotiations occurred. Operational continuity challenges persisted across ASST Rhodense’s healthcare facilities due to the unresolved system outages.

Sources
Sources available to members
1 source