LockBit ransomware hit three German hospitals run by KHO on Christmas Eve
- Organization
- Katholische Hospitalvereinigung Ostwestfalen
- Exploit
- Ransomware
- Industry
- Healthcare
In the early hours of December 24, 2023, the IT systems of three hospitals operated by Katholische Hospitalvereinigung Ostwestfalen (KHO) failed at the same time. The affected sites were Franziskus Hospital in Bielefeld, Sankt Vinzenz Hospital in Rheda-Wiedenbrück and Mathilden Hospital in Herford.
KHO said attackers had gained access to its infrastructure and deliberately encrypted data. Early analysis pointed to LockBit 3.0, the ransomware-as-a-service operation. Staff shut down all systems immediately as a precaution and convened a crisis team drawing on internal and external IT security specialists. The central cybercrime contact point for North Rhine-Westphalia and specialists from the Dortmund police were brought in.
The hospital group said medical treatment continued and that patient records remained available, with clinic operations running under minor technical restrictions. As a safety measure the three sites deregistered from emergency care, so ambulances were routed elsewhere while systems were restored.
By the end of December LockBit had not added KHO to its leak site, so it was not clear whether patient or staff data had been copied before encryption. KHO did not disclose any ransom demand. The incident was one of several attacks on German hospitals around the Christmas period.