Lockbit 3.0 Ransomware Disrupts Emergency Care at Multiple German Hospitals

Stu Sjouwerman | Jan 3, 2024

Hospitals Continue to be RansomwareHitting three hospitals within a Germany-based hospital network, the extent of the damage in this confirmed ransomware attack remains undetermined but has stopped parts of operations.

It appears that affiliates of ransomware gangs have forgotten the golden rule – you don’t hit hospitals.  It’s one thing to disrupt operations at a regular brick and mortar business. But hitting a business where someone’s life could be literally placed in jeopardy because a system is unavailable?  That’s downright sub-human.

And this is exactly what happened on Christmas eve, no less, to three hospitals within the German-based hospital network, Katholische Hospitalvereinigung Ostwestfalen (KHO). According to a Google translation of their announcement of the attack, the attack happened in the early morning, causing all systems to be shut down as a precaution. 

While the extent of the damage is unclear, some impact can be inferred from their notes on which services are available.  According to the announcement, “Patient care is still guaranteed and the clinic continues to operate with slight technical restrictions, but we have withdrawn from emergency care for safety reasons.”

Since Lockbit 3.0 is offered as a service, it’s up to the affiliates to use their initial attack vector of choice. With many affiliates simply taking advantage of dark and clear web malicious services such as OLVX, access via compromised credentials remains one of the leading means of initial access…. Which puts the onus on organizations to educate their users (via new-school security awareness training) on how to see malicious phishing emails and web-based social engineering for what it really is – the starting point for a cyber attack.

KnowBe4 enables your workforce to make smarter security decisions every day. Over 65,000 organizations worldwide trust the KnowBe4 platform to strengthen their security culture and reduce human risk.

Ransomware Simulator

Free downloadable software tool

Threat actors are constantly coming out with new strains to evade detection. Is your network effective in blocking all of them when employees fall for social engineering attacks?

RanSim gives you a quick look at the effectiveness of your existing network protection. RanSim will test 24 ransomware infection scenarios and 1 cryptomining infection scenario and show you if a workstation is vulnerable.

RansIm-Monitor3Here's how it works:

  • 100% harmless simulation of real ransomware and cryptomining infections
  • Does not use any of your own files
  • Tests 25 types of infection scenarios
  • Just download the installer and run it
  • Results in a few minutes!

Get RanSim!

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.