NEWS
HSE Systems Went Down After a Vendor Got Hit by Ransomware
Ireland’s HSE lost email and system access for hours on June 4 after a third-party vendor was hit by ransomware, the third such incident since 2021.
HSE computer systems across Ireland went dark for several hours on June 4, 2026, cutting off email and telephone access at sites nationwide before the health service confirmed all systems had been restored that afternoon. The Journal, the Dublin-based news outlet that first reported the cause, found that the outage followed a ransomware attack on a third-party company holding data belonging to the HSE, though the health service’s public statement made no mention of ransomware.
Ireland’s publicly funded health service has spent an estimated €102 million recovering from the 2021 Conti ransomware attack, with the state’s spending watchdog estimating another €657 million over seven years will be needed to complete the security overhaul recommended after that breach. The gap that caused the June 4 disruption ran through a vendor’s systems, somewhere outside that investment’s reach.
A Spokesperson Called It a Networking Problem
The HSE’s official response covered what it controlled. “There was a technical issue this afternoon which impacted HSE internet traffic. As a result of this technical issue, there was limited or no access to several national IT and telephone systems for a number of hours,” the spokesperson said, confirming access had since been restored.
It was a networking problem and not related to any cybersecurity issue.
That phrase, networking problem, was the health service’s only public description of what had caused several national IT and telephone systems to go offline.
Staff across the health service reported the afternoon differently. Email went inaccessible. Internet access dropped. At one Dublin hospital, an internal message told staff of “widespread issues ongoing” with one of its central systems, noting the problems were affecting new users trying to log in. The disruption, per the HSE’s own statement, covered multiple national IT and telephone systems for a number of hours.
A source told The Journal that the HSE had not been directly targeted. A third-party company holding data belonging to the HSE had become the subject of a ransomware attack, and the disruption to HSE systems was the downstream consequence.
The HSE’s statement covers the health service’s own network traffic and confirms restoration. It says nothing about the third-party company, the ransomware attack on that company, or the status of any HSE data the company held at the time. Whether patient or staff records were accessed or exfiltrated remains publicly unanswered.
What the Conti Attack Left Behind
The Longest Eight Weeks
On May 14, 2021, the HSE shut down its entire IT infrastructure after discovering its systems had been encrypted by Conti ransomware, deployed by Wizard Spider, a criminal group believed to be operating from Russia. The initial compromise dated to March 18, when a malicious Microsoft Excel file was opened on a staff workstation. The health service’s antivirus software detected malicious activity on March 31 but was set to monitor mode rather than protect mode, so nothing was blocked. The hackers operated inside the network for approximately eight weeks before triggering the ransomware at 4am on May 14. The group issued a ransom demand of just under $20 million, threatened to sell or publish stolen patient data if it went unpaid, then provided a free decryption key a week later without receiving payment. No ransom was paid.
The fallout lasted months. Hospitals reverted to paper records. Approximately 7,000 patient appointments were delayed each day during the worst of the disruption. Radiology services went offline across multiple hospitals, affecting CT and other scans. Cancer and stroke services were disrupted. The National Maternity Hospital warned of significant service disruption. Full restoration took until September 21, 2021, according to a lessons-learned assessment by the U.S. Department of Health and Human Services, which described the incident as the largest known attack against a health service computer system in history.
A 157-page post-incident review by PricewaterhouseCoopers (PwC), commissioned by the HSE and published in December 2021, found tens of thousands of outdated Windows 7 systems still running across the HSE network, no documented incident response plan, and no single executive accountable for cybersecurity. High-risk gaps existed in 25 of the 28 controls analysts consider most effective against human-operated ransomware attacks.
The Cost and the Claims
The financial and legal fallout from the 2021 HSE cyberattack was still being processed four years after the breach:
- €102 million: the HSE’s confirmed direct-cost estimate for the attack
- 90,936: patients and staff notified that their personal data had been compromised
- 473: legal proceedings filed against the HSE arising from the breach as of mid-2024, with additional claims relating to psychological harm from the data exposure
- €750: the per-person compensation offer the HSE began extending to affected individuals from December 2025, more than four years after the attack
Ireland’s state spending watchdog, the Comptroller and Auditor General, estimated in 2024 that the HSE would need to spend almost €657 million over seven years to fully implement the security improvements the PwC review had recommended.
The Same Entry Point, Two More Times
The June 2026 outage has a direct predecessor. In June 2023, the HSE discovered it had been caught up in the global MOVEit Transfer attack. Professional services firm EY was using MOVEit Transfer, a managed file-transfer product made by Progress Software Corporation, to automate an HSE recruitment process when the Cl0p ransomware group (also identified in security reporting as Lace Tempest) exploited a critical SQL injection vulnerability in the software. The attack swept through hundreds of organizations globally, among them the BBC, British Airways, Aer Lingus, and U.K. payroll provider Zellis. Cl0p had exploited the same flaw simultaneously across dozens of countries in one of the more significant supply-chain ransomware incidents of that year. On June 8, the HSE determined that data belonging to approximately 20 individuals on a recruitment panel had been accessed; the exposed information included names, addresses, mobile numbers, and panel positions. No patient data was involved, and operational systems stayed up.
Contained by comparison. But the entry point was a third-party company with access to HSE data, breached through that company’s own systems. That is the same description sources give for June 4, 2026.
| 2021 Conti Attack | 2023 MOVEit/EY Breach | June 2026 Outage | |
|---|---|---|---|
| Attack vector | Phishing email to HSE employee | Third-party software (MOVEit Transfer) | Third-party data company (ransomware) |
| HSE systems offline | Full IT shutdown | No | National IT and phones, several hours |
| Data compromised | ~91,000 patients and staff | ~20 recruitment-panel individuals | Unknown |
| Recovery time | Four months | Days | Several hours |
| Direct cost | €102 million | Minimal | Unknown |
All three incidents reached the HSE through a party outside its direct control (a staff member in the first case, a contractor’s software in the second, a data-holding vendor in the third). Each time, the breach came from a direction the health service’s own defenses were not covering.
Healthcare’s Vendor Perimeter Problem
The Targeting Logic
The June 4 incident fits a pattern that dominated healthcare cybersecurity in 2025. The FBI’s Internet Crime Complaint Center (IC3) reported healthcare as the most targeted critical infrastructure sector for ransomware that year, with 460 documented incidents.
Healthcare organizations are attractive targets because patient data holds long-term value for fraud and identity theft, and because operational dependence on live clinical systems creates leverage that drives ransom payments. By 2025, cybercriminal groups had moved their focus upstream, hitting vendors, contractors, and managed service providers rather than health systems directly. One compromised vendor with privileged data access can expose dozens of downstream organizations in a single operation. Ransomware groups now routinely combine encryption with data theft, threatening to publish or sell stolen records if payment is not received – a double-extortion model that has defined most major healthcare attacks since 2021.
Attacks Through Vendor Relationships
The scale of vendor-based attacks is visible in specific cases. New York City Health + Hospitals (NYC H+H), the largest public hospital network in the United States, disclosed in early 2026 that attackers had accessed its systems from late November 2025 through February 2026 via a third-party vendor, affecting 1.8 million individuals with exposed data including medical, biometric, and financial records. The Change Healthcare ransomware attack of February 2024 hit a U.S. healthcare billing intermediary processing transactions for a large share of the country’s hospitals, exposing data for more than 190 million Americans in the largest healthcare data breach on record. ChipSoft, whose hospital management software runs in 70-80% of Dutch hospitals, was hit by ransomware in 2026, forcing multiple Dutch healthcare institutions to take systems offline as a precaution.
The pattern is direct: attackers bypass a health system’s own defenses by reaching it through a supplier. Once inside a supplier’s network, they can access the health organization’s data without ever attacking the health organization directly. Security specialists speaking to RTÉ in May 2026, on the fifth anniversary of the 2021 attack, noted that attackers’ ability to exploit vendor ecosystems had grown substantially since then, accelerated by artificial intelligence tools. Ireland’s cybersecurity sector now encompasses more than 630 firms employing around 8,000 professionals.
The Remaining Security Bill
What the HSE Has Built
The HSE has invested in its own defenses since 2021. By late 2023, the health service had committed to a five-year, €33 million contract for threat detection and extended detection and response (EDR) services, with combined procurement documentation citing an estimated value of €60 million across two lots. EDR services consolidate security telemetry across endpoints, networks, and cloud environments, allowing security teams to identify threats faster and contain incidents before they spread. The procurement documents described the new infrastructure as designed to “minimise the risk of data breaches and other security incidents” and to support the HSE’s “wider eHealth strategy.”
Progress on governance gaps has been slower. In May 2024, during Seanad debates on the third anniversary of the 2021 attack, it emerged that senior cybersecurity roles at the HSE had still not been filled on a permanent basis. Some devices across the health service were still running Windows 7, the same outdated operating system the PwC review had specifically flagged as a core vulnerability three years earlier.
The Vendor Gap
The Comptroller and Auditor General’s €657 million seven-year program is a projection of what needs to be built, not a record of completed work. The program addresses the HSE’s own security architecture. Vendor risk management is a distinct discipline, requiring healthcare organizations to assess a supplier’s security practices before contracting, set enforceable standards the supplier must meet, and maintain monitoring for signs of supplier compromise throughout the relationship. The largest U.S. health systems built formal vendor risk programs in the wake of the Change Healthcare breach, which illustrated how completely a single intermediary’s compromise could disrupt patient care at national scale. Whether the HSE’s seven-year program explicitly addresses vendor risk management, or whether that falls to individual contract terms negotiated with each third-party data holder, has not been established from public procurement records.
The HSE has not confirmed whether patient data held by the third-party company attacked on June 4 was accessed or exfiltrated during the ransomware incident.
-
AI2 months agoOracle Cuts 21,000 Jobs in a Year, Cites AI in 10-K Filing
-
AI2 months agoFable 5 and Mythos 5 Return as US Lifts Anthropic Export Controls
-
AI2 months agoSpaceX’s Google Deal Turns a Rocket Company Into a Cloud Landlord
-
GAMING2 months agoCD Projekt Red Co-CEO: Redemption Arc Isn’t Done, Witcher 4 in 2027
-
CRYPTO2 months agoXPL Rallies 30% Ahead of Plasma One Card Tier Launch
-
NEWS2 months agoGoogle Search Profiles Build a Follow Graph Inside Discover
-
APPS2 months agoDGO App Brings Rs 549 Mobile Pass for FIFA World Cup 2026 in Nepal
-
AI2 months agoMoonshot AI Targets $30 Billion in China’s Fastest AI Funding Sprint
