The Conti ransomware gang failed to encrypt the systems of the Irish Department of Health (DoH) despite breaching its network and dropping Cobalt Strike beacons to deploy its malware onto the network. On the same day, the hackers breached the network of the country’s public health system (HSE), forcing it to shut down all of its IT systems in order to limit the scope of the attack.
The Irish Department of Environment, Climate and Communications said the following: “The National Cyber Security Centre (NCSC) was made aware on 13 May that hackers attempted to attack the Department of Health. This attempted attack remains under investigation, however there are indications that it was a ransomware attack similar to that which affected the HSE.”
Read also: Conti ransomware gang demands $20 million from Irish HSE

The NCSC provided more details about the attack and confirmed the connection between the two incidents, saying that the two "attacks are believed to be part of the same campaign targeting the Irish healthcare sector."
The NCSC was alerted to suspicious activity on the Ministry of Health's network on the afternoon of May 13th.
Researchers discovered Cobalt Strike beacons deployed on the network, a tool commonly used by ransomware gangs to deploy malicious payloads and encrypt systems across the network.
The following morning, a Conti ransomware attack disabled some of the HSE's devices, forcing the health service to shut down its entire IT infrastructure to limit the impact.

See also: New threat: Ransomware attacks with triple extortion
Around the same time, a second Conti attack attempting to execute ransomware payloads to encrypt the systems of the Irish Ministry of Health was blocked by antivirus software and tools developed by researchers the previous day.
The Irish government said in a statement: “The Department of Health has implemented a response plan, including suspending certain functions of its IT system as a precaution.”
The NCSC also noted that the ransomware sample used during these attacks appends the .FEEDC to encrypted files. Conti's gang claimed to have accessed the HSE network for over two weeks and managed to steal 700GB of unencrypted files, including employee and patient details, financial statements, payroll and contracts.

He also said that the HSE would have to pay a $9,999,000 ransom for the gang to delete all stolen data from its servers and provide a decryptor.
Proposal: AXA Insurance: Ransomware targeted Asian branches
Although the incident has led to widespread disruption affecting Ireland's healthcare services, the Irish Prime Minister, Taoiseach Micheál Martin, has stated that the HSE will not pay the ransom demanded.
Conti ransomware is a Ransomware-as-a-Service (RaaS) operation believed to be operated by a Russian hacking group known as “Wizard Spider.” Conti shares the same code as the Ryuk Ransomware, whose TrickBot-powered distribution channels took over after Ryuk’s activity declined around July 2020.
Previously, the Conti ransomware gang also hit the Scottish Environmental Protection Agency (SEPA) and leaked around 1.2GB of stolen data on its data leak site on the dark web.
Information source: bleepingcomputer.com
