LUP-Kliniken
Incident posture
Linked entities
- Victim
- LUP-Kliniken
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A cyberattack affected the LUP-Kliniken in the Ludwigslust-Parchim district, targeting the Hagenow and Ludwigslust locations. The incident was discovered overnight, prompting authorities to proactively disconnect both facilities from the communication network, rendering email and website services inaccessible. Despite the disruption, patient care continued, with emergency services handling life-threatening cases while the emergency departments were formally logged off. The state criminal police office initiated an investigation into computer sabotage and data espionage offenses, deploying specialists to secure digital evidence on-site. The incident marked the fourth reported case of computer sabotage in the region this year.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In the early hours of February 10, 2025, a cyberattack was detected affecting the LUP-Kliniken, the hospital facilities operated under the Landkreis Ludwigslust-Parchim in the German state of Mecklenburg-Vorpommern. The attack was discovered during the night leading into the day of the announcement. According to information released by the Landkreis, both clinic locations in Hagenow and Ludwigslust became unreachable via electronic mail and through their website following the discovery of the intrusion. As an immediate precautionary measure, both facilities were disconnected from the broader communication network in order to limit potential spread of the incident and to allow technical staff to begin assessing and addressing the situation. The cyberattack was officially identified as a case of computersabotage, with investigative authorities confirming that probes would examine both the sabotage itself and potential unauthorized access to data.
The impact of the incident extended primarily to the digital and administrative infrastructure of the two affected hospital sites rather than to direct medical care. The Landkreis communicated that medical care at the locations remained secured, ensuring that patients continued to receive treatment within the capabilities of the facilities during the response phase. The emergency department at the affected sites was officially deregistered from regular emergency response routing, meaning that new emergency cases would not be directed there in the ordinary course. However, critically threatening emergencies continued to be treated at the locations, preserving essential urgent medical response capacity for those already arriving or in immediate need. This partial continuity of services indicates that the disruption was focused on communication and networked systems rather than on the operational capacity to deliver bedside care.
In response to the discovery of the attack, technical specialists were deployed on site to secure digital traces and begin the process of remediation. The Landkreis reported that work was actively underway to resolve the technical problems stemming from the attack. The State Criminal Police Office (Landeskriminalamt) took over the criminal investigation, opening proceedings for violations related to computersabotage and the unauthorized interception or espionage of data. These legal classifications under German criminal code reflect both the deliberate disruption of technical infrastructure and the potential exposure of sensitive information during the attack. Specialists on site were tasked with preserving forensic evidence to support the investigation.
The LUP-Kliniken incident was characterized in early reporting as the fourth instance of computersabotage recorded in Mecklenburg-Vorpommern within the calendar year 2025. This contextual detail was provided by the authorities as part of the initial communication, highlighting a broader pattern of such incidents within the state. Further specifics regarding the precise nature of the attack, the threat actor involved, the extent of any data compromise, or the timeline for full restoration of communication services were not disclosed in the initial reporting from the Landkreis or its investigative partners. As a result, the publicly available details remain limited to the immediate operational and investigative response, with additional information expected to emerge as the forensic and criminal investigations progress.
Sources
Sources available to members: 1 source.