In February 2024, the Romanian National Cyber‑Security Centre (DNSC) faced a cyber‑attack that had breached a popular medical software provider, RSC, and spread across hospitals nationwide. The attackers, using a ransomware strain called BackMyData, encrypted patient records and demanded a €160,000 ransom in bitcoin.
Stormed by alarm calls from hospitals, the DNSC had little choice but to order the immediate disconnection of all affected facilities from the internet. The decision was a hard one, but it bought critical time for IT teams to assess the infection and fight back.
With no connected devices, emails or web browsing, doctors and nurses had to revert to pen and paper. In hospitals such as Buzău and Pitești, staff created manual logbooks and arranged for laboratory results on paper, while other teams used off‑line tools like Excel to keep patient safety on track.
Cyber‑experts worked through the night, mitigating the malware and restoring backup copies, while communications officers kept hospitals and the public informed. The DNSC urged patients to avoid unnecessary hospital visits and refused to engage with or pay the ransom.
Within five days most hospitals were back online, operating near normal with no reported deaths or serious harm. However, some data recorded on paper was lost, and the incident underscored the vital role of up‑to‑date backups and resilient cyber‑security practices.
The attack helped draw attention to the broader risk of increasing digitisation in healthcare, a trend echoed by other incidents such as the 2024 NHS hack in the UK and ransomware campaigns in the US. It has become a case study for disaster planners worldwide, illustrating how the intersection of medical care and cyber‑risk can be managed in crisis.
















