German hospital network Katholische Hospitalvereinigung Ostwestfalen (KHO) has confirmed that recent service outages at three of its hospitals were caused by a Lockbit ransomware attack
See also: LockBit ransomware says it hacked Essendant

The attack occurred on Saturday morning, December 24, 2023. It severely affected the systems supporting the operation of three hospitals in the Bielefeld, Rheda-Wiedenbrück and Herford regions in Germany.
“ Unknown malicious actors managed to gain access to the hospital’s IT infrastructure systems and encrypted data ,” the hospital’s machine translation states
Currently, investigations are underway to determine the extent of the damage and whether the attackers stole data.
The three hospitals, which operate under the KHO, have been affected by the cyberattack:
- Franziskus Hospital Bielefeld – With 614 beds and ten specialized departments, the center employs 390 doctors and staff.
- Sankt Vinzenz Hospital Rheda-Wiedenbrück – The hospital has 614 beds and includes five specialized clinics, with more than 200 doctors and staff.
- Mathilden Hospital Herford – The hospital has 614 beds and eight specialist clinics, with 230 doctors and staff.
The above hospitals play a critical role in providing health services in their respective locations , so a cyberattack affecting their IT systems could have serious consequences for people in medical emergencies.
See also: LockBit: Still the most serious ransomware threat
The announcement from the KHO clarifies that patient care continues normally at the affected hospitals and all clinical functions remain available, although with some technical restrictions. Essential information for patients is accessible through the successful restoration of backup copies.

However, in case of a need for medical care, the three hospital units of KHO are unable to provide emergency care, resulting in people who require immediate medical attention being redirected elsewhere, potentially with serious delays.
At present, the Lockbit ransomware group has not added KHO to its dark web, so it has not yet been determined whether the cybercriminals stole patient data or other sensitive information.
Users can protect themselves from Lockbit in various ways. First, it is important to keep their software up to date. Lockbit, like many other ransomware, exploits vulnerabilities in older software versions to infiltrate systems.
Secondly, users should be careful with the emails and file attachments they receive. Lockbit is often spread through phishing emails that contain malicious attachments or links.
Third, using strong antivirus can help protect against Lockbit. Antivirus software can detect and remove ransomware before it can lock a user's files.
See also: LockBit ransomware: Gang earned $91 million through 1,700 attacks on US organizations
Finally, creating regular backups of important files can be vital. If the user becomes a victim of Lockbit, the backups can be used to recover the files without having to pay a ransom.
Source: bleepingcomputer
