Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationhealthcare-sector-threatoperational-disruptionunderground-data-leak

Conti Ransomware Crippled Ireland’s Health Service and Exposed Stolen Data

Updated 1mo agoFirst seen May 25, 202612 sources

Ireland’s Health Service Executive (HSE) was hit by a major Conti ransomware attack that forced the shutdown of national health IT systems, disrupted hospital clinics, maternity services, radiology, GP referrals, and parts of Covid-19 testing and contact tracing, while emergency care and the vaccination programme continued. Irish officials said the attack began early on a Friday morning, described it as one of the most serious cybercrime incidents ever faced by the state, and confirmed the government would not pay a bitcoin ransom. Investigators also examined related hostile activity, including an attempted intrusion at the Department of Health and earlier distributed denial-of-service activity, while Gardaí, the National Cyber Security Centre, Defence Forces, Europol, and outside cybersecurity experts joined the response.

The attackers were reported to have demanded about $20 million and claimed to have stolen roughly 700 GB of data, raising fears that patient and employee information could be leaked on dark-web extortion sites. Recovery was expected to take weeks as the HSE rebuilt systems and shifted many services to manual processes, while the health service sought court injunctions to restrain the sharing of hacked data. The financial fallout later climbed to about $600 million, and the long tail of the breach continued years later, with the HSE offering compensation to some victims affected by the system-wide cyberattack.

Share:
Conti Ransomware Crippled Ireland’s Health Service and Exposed Stolen Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Dec 9, 20257mo ago

HSE offers €750 to victims of the cyberattack

In December 2025, the HSE offered €750 to people affected by the system-wide cyberattack. This indicates a later compensation step tied to the long-term consequences of the 2021 incident.

Jun 28, 20215y ago

Estimated cost of HSE ransomware attack reaches $600 million

By late June 2021, reporting said the costs associated with the ransomware attack on Ireland's health system had reached about $600 million. The figure reflected the extensive recovery effort and the broad operational and financial impact of the incident.

May 20, 20215y ago

HSE obtains court injunctions against sharing stolen data

On 2021-05-20, the HSE secured High Court injunctions restraining the sharing, processing, or sale of data taken in the attack. The legal move aimed to limit further dissemination of hacked information if it appeared online or was traded by third parties.

May 19, 20215y ago

Government says HSE recovery will take several weeks

On 2021-05-19, Irish officials said restoring the HSE's IT environment would take several weeks. The statement underscored the scale of operational damage and the prolonged impact on healthcare services.

May 18, 20215y ago

Authorities monitor dark web for leaked HSE data

By 2021-05-18, Irish authorities were monitoring dark web leak sites for any publication of data stolen from the HSE. This reflected growing concern that sensitive health and employee information might be exposed publicly.

May 15, 20215y ago

Attackers reportedly demand $20 million and claim data theft

Reports published on 2021-05-15 said the attackers were demanding about $20 million and claimed to have spent two weeks in the HSE network. They also alleged they had stolen roughly 700 GB of unencrypted data, including patient, employee, financial, and payroll information.

Officials identify Conti and assess broader targeting

By 2021-05-15, investigators were profiling the malware as Conti ransomware and described the incident as a targeted attack by a serious international criminal group. Authorities also examined a related attempted attack on the Department of Health and prepared checks for other State agencies in case the intrusion had spread.

May 14, 20215y ago

Irish government says it will not pay the ransom

On the day of the attack, Irish officials said a bitcoin ransom demand had been received or reported but that the State would not pay. Authorities including the HSE, National Cyber Security Centre, Gardaí, Defence Forces, and outside experts began incident response and recovery efforts.

Ransomware attack hits Ireland's HSE and forces IT shutdown

Around 4:30 a.m. on 2021-05-14, Ireland's Health Service Executive suffered a major ransomware attack that led it to shut down national IT systems as a precaution. The disruption affected hospital clinics, imaging, referrals, and some Covid-19 services, while emergency care and vaccinations continued.

Mar 16, 20215y ago

PwC traces HSE breach to phishing email opened on patient-zero workstation

A PwC investigation found the HSE intrusion began on 2021-03-16 when a user opened a malicious Microsoft Excel attachment from a phishing email on the patient-zero workstation. The report said the attackers likely later exploited an unpatched known vulnerability to reach Active Directory before deploying Conti ransomware.

Ireland Conti ransomware attack vector was spam email
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Conti Ransomware Crippled Ireland’s Health Service and Exposed Stolen Data | Mallory