CSIDB logo
Incident

Institut de Formation Santé de l'Ouest

Incident posture

Attack window
Mar 2021
Location
France
Status
Historical
CIA posture
Available to members
Updated
2025-10-25 00:00

Linked entities

Victim
Institut de Formation Santé de l'Ouest
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Mar 2021
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware group infiltrated the Institut de formation Santé de l'Ouest, exfiltrating hundreds of internal documents containing sensitive employee information and patient records from EPHAD facilities, including psychological evaluations, health data, and incident reports. The attackers publicly leaked four compressed data containers on the darkweb as part of extortion efforts, though the institution did not comply with ransom demands, resulting in permanent loss of the stolen healthcare information.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

The Institut de formation Santé de l'Ouest, a healthcare training institute in France, experienced a ransomware attack beginning on March 25, 2021. Cybercriminals infiltrated the organization's systems over several days before publicly threatening to release stolen data. The attackers exfiltrated hundreds of internal documents containing sensitive health information, which they subsequently published on dark web platforms as leverage for extortion. Four compressed file containers were made available online by the threat actors, demonstrating their access to the institute's systems and intent to pressure the organization into paying ransom demands. The compromised data included confidential records pertaining to both employees and patients, with particular focus on individuals associated with EPHAD care facilities for the elderly.

Patient records exposed in the breach contained psychological evaluations, medical histories, and reports of incidents occurring within care facilities. The attackers employed standard ransomware group tactics by simultaneously encrypting systems and stealing sensitive data to maximize pressure on the victim organization. Analysis of the attack timeline suggests the initial compromise occurred on March 25, with data exfiltration and system infiltration continuing until the threat actors published their ultimatum. Healthcare institutions in France generally maintain policies against paying ransoms due to constrained budgets and ethical considerations, resulting in permanent loss of the stolen data according to standard practice. The incident exemplified broader targeting of healthcare entities by cybercriminals despite the sector's limited financial resources, with patient privacy and institutional operations suffering primary impacts from the unauthorized disclosure of medical records.

Sources

Sources available to members: 1 source.

CSIDB