ClosedLow impactAI Refreshed

Romanian Hospital Ransomware Attack via Medical Software Supply Chain (Feb 2024)

Occurred 10 Feb 2024·Detected 23 Jun 2026·
🇷🇴 Romania, primarily Bucharest and hospitals nationwide including Buzău and Pitești2 reportsEnded 29 Jun 2026
CyberCyber

Retrospective case study of the February 2024 'BackMyData' ransomware attack that infected 26 Romanian hospitals via a supply-chain compromise of medical software vendor RSC (Hippocrates system). Over 100 hospitals were proactively disconnected and ran on pen-and-paper for up to five days. A €160,000 ransom was refused; no patient deaths or serious harm were reported. Attribution to a specific gang remains unconfirmed by Romanian police, though a related gang's site was taken down and four Russians were arrested abroad. Romanian DNSC coordinated the national response. No insurance claims, final financial losses, or market-moving pricing actions have been disclosed.

AI-generated from linked source reports. See our correction policy.

Impact verdict

Low impact. Loss pathway remains bounded: ransom was refused; disruption was contained within approximately five days; no patient deaths or serious harm were reported; no insured-loss estimate, no named commercial insured, and no evidence of market-moving pricing, capacity, or reinsurance action. The event is material as a healthcare cyber supply-chain case study, not as a quantified London Market loss. Material constraints persist: no insurance claims data, no police-confirmed attribution, and no final financial loss figures.

View assessment methodology

Premium discovery tier

Unlock analyst briefs, intelligence depth, and the revision timeline

Public pages show event facts and a short lead-in. Premium accounts unlock analyst briefs, deeper intelligence, loss context, and the full revision history for this event.

Start two-week trial

Affected countries

🇷🇴 Romania

Lloyd's classifications

Tracking this kind of risk? Get an email when Cyber events escalate.

Get alerts