A threat brief published by the US Department of Health and Human Services (HHS) on Thursday paints a grim picture of how Ireland's health service, the HSE, was overwhelmed and had 80% of its systems encrypted during
last year's Conti ransomware attack.
This led to
severe disruptions of healthcare services throughout Ireland and exposed the information of thousands of Irish people who received COVID-19 vaccines before the attack after roughly 700 GB of data (including protected health information) was stolen from HSE's network and sent to attackers' servers.
The short incident report [
PDF], based on a PwC independent post-incident review [
PDF] commissioned by the Board of the HSE in June 2021, reveals that the impact of this attack on HSE's IT environment was primarily caused by the organization's lack of preparedness to deal with such an incident.