Second French hospital forced to relocate patients after cyber attack this year
The hospital shut down its network as a precaution after a south Parisien hospital had to do the same in August
A hospital in France has been hit with a cyber attack and been forced to move patients out of its facility, the second case of its kind in the country this year.
The attack hit the André Mignot hospital in Versailles on Saturday 3 December, according to the Agence régionale de santé (ARS) Île-de-France, France’s regional health service, prompting it to shut down its network as a security measure.
It said that no other health facility had been impacted by this cyber attack. The National Authority for Security of Information Systems (ANSSI), the agency in charge of the country’s computer security, is also carrying out an investigation into the incident.
“Cyber criminals know that hitting patient services and business availability is the most effective way to gain a ransom payment,” said Simon Chassar, CRO at Claroty. “The healthcare industry is one of the few sectors where cyberattacks can fatally impact human life, and threat actors know this.
“They want to put decision-makers in a morally impossible situation so that they have no choice but to pay ransoms in order to get their services back up and running. Unfortunately, situations like this are likely to increase as healthcare providers add more cyber-physical systems to their networks.”
André Mignot was forced to transfer some patients to other hospitals and is only accepting a limited number of new patients. In case of an emergency, patients are advised not to go to the site but dial 15 to reach the French Medical Services (SAMU) instead and receive instructions on where to go. ARS said it’s on-site and organising continuity of care and management of patients at a regional level with the SAMU.
The hospital has also enacted emergency measures including a “white plan”, where hospitals can reorganise internal spaces or transfer patients to other services, as well as pushing back the date for operations that are less urgent. It has also partially paused its operating theatre activities.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
RELATED RESOURCE
Accelerating healthcare transformation through patient-centred medtech solutions
Seize the digital transformation opportunities to streamline patient care and optimise patient outcomes
ARS Île-de-France has advised other healthcare establishments in the region to be vigilant in case there are more cyber attacks. The agency has also created a crisis unit to allow it to monitor the situation, support its teams, and coordinate care between hospitals.
The attack on André Mignot follows a similar incident from August 2022 when the LockBit ransomware group was thought to have attacked a hospital near Paris and demanded a ransom of $10 million.
The cyber attack was confirmed to have occurred on 21 August by the Center Hospitalier Sud Francilien (CHSF) and was reported to have been forced to turn patients away too.
Zach Marzouk is a former ITPro, CloudPro, and ChannelPro staff writer, covering topics like security, privacy, worker rights, and startups, primarily in the Asia Pacific and the US regions. Zach joined ITPro in 2017 where he was introduced to the world of B2B technology as a junior staff writer, before he returned to Argentina in 2018, working in communications and as a copywriter. In 2021, he made his way back to ITPro as a staff writer during the pandemic, before joining the world of freelance in 2022.
-
Trump's AI executive order could leave US in a 'regulatory vacuum'News Citing a "patchwork of 50 different regulatory regimes" and "ideological bias", President Trump wants rules to be set at a federal level
-
TPUs: Google's home advantageITPro Podcast How does TPU v7 stack up against Nvidia's latest chips – and can Google scale AI using only its own supply?
-
15-year-old revealed as key player in Scattered LAPSUS$ HuntersNews 'Rey' says he's trying to leave Scattered LAPSUS$ Hunters and is prepared to cooperate with law enforcement
-
The Scattered Lapsus$ Hunters group is targeting Zendesk customers – here’s what you need to knowNews The group appears to be infecting support and help-desk personnel with remote access trojans and other forms of malware
-
Impact of Asahi cyber attack laid bare as company confirms 1.5 million customers exposedNews No ransom has been paid, said president and group CEO Atsushi Katsuki, and the company is restoring its systems
-
The US, UK, and Australia just imposed sanctions on a Russian cyber crime group – 'we are exposing their dark networks and going after those responsible'News Media Land offers 'bulletproof' hosting services used for ransomware and DDoS attacks around the world
-
A notorious ransomware group is spreading fake Microsoft Teams ads to snare victimsNews The Rhysida ransomware group is leveraging Trusted Signing from Microsoft to lend plausibility to its activities
-
Volkswagen confirms security ‘incident’ amid ransomware breach claimsNews Volkswagen has confirmed a security "incident" has occurred, but insists no IT systems have been compromised.
-
The number of ransomware groups rockets as new, smaller players emergeNews The good news is that the number of victims remains steady
-
Teens arrested over nursery chain Kido hacknews The ransom attack caused widespread shock when the hackers published children's personal data
