august

The Conti Attack on Ireland's Health Service, 2021

The Shutdown

The calls began around four o'clock on the morning of Friday, May 14, 2021. Ireland's Health Service Executive — the body that runs the country's public health system, the largest employer in the state, with roughly 130,000 staff across fifty-four acute hospitals and some four thousand other locations — was being told that ransomware was executing across its network. Encryption had started in the small hours. By the time senior officials were awake, it was clear the intrusion was not confined to one hospital or one region. It was national.

The decision taken before dawn had no obvious precedent among the world's health systems: the HSE switched off everything. Every national application, every connection into the National Healthcare Network — the wide-area network stitching hospitals, community services, and administrative offices together across the country — was shut down by the HSE itself, on the logic that any machine still reachable was a machine still at risk. The attackers had encrypted roughly 80 percent of the HSE's environment. The shutdown took the remaining 20 percent offline too.

Ireland's hospitals opened that Friday to dead screens. Radiology systems were gone, so scans could not be viewed or ordered; laboratory systems were gone, so blood results moved by phone and by hand. Radiotherapy was suspended at cancer centers. Dublin's Rotunda, one of the country's main maternity hospitals, canceled outpatient appointments that morning, asking only women at least thirty-six weeks pregnant to attend. General practitioners lost the electronic channels they used to refer patients — including, in the middle of a pandemic, referrals for COVID-19 tests, which reverted to telephone. The COVID-19 vaccination program largely continued; its registration systems, built hastily and hosted separately during the pandemic, sat outside the affected estate.

Clinicians did what clinicians in Britain had done four years earlier, as chronicled in the WannaCry chapter: they reverted to paper and kept the patients moving. The difference was scale and duration. WannaCry crippled a third of England's hospital trusts for days. Conti took essentially all of Ireland's public health IT, and the recovery would be measured in months.

The Intrusion

The email that began the intrusion was sent on March 16, 2021, and opened two days later, on March 18, when a user at a single HSE workstation clicked on the attached Microsoft Excel file. A malicious macro ran, malware executed, and the attackers had their foothold. The post-incident investigators would later label the machine the Patient Zero Workstation.

For eight weeks the intruders — an affiliate of the Conti ransomware operation — moved through the network, using Cobalt Strike, the commercial penetration-testing tool that criminal groups had adopted as their standard implant. They harvested credentials, escalated privileges, and spread from the HSE's central systems into hospitals, both statutory and voluntary. The National Healthcare Network was, in the investigators' description, largely flat: once inside, the attackers could reach almost every part of it.

Defenders saw parts of the intrusion as it happened. On March 31, antivirus software flagged Cobalt Strike activity on the Patient Zero Workstation itself — but the tool was configured in monitoring mode rather than blocking mode, and the detection led nowhere. In the second week of May, as the attackers began final preparations, alarms multiplied. Two hospitals identified malicious activity on their systems in the days before the attack and responded locally, without triggering any wider alert. On May 12 and 13, the HSE's security provider flagged unhandled threat events on more than a dozen systems. None of the signals produced a coordinated response.

Ireland's Department of Health — a separate organization with its own network — had been penetrated the same week by the same attackers with the same tooling. There, suspicious activity was detected on May 13, defenses reacted, and when the ransomware attempted to execute in the early hours of May 14 it was blocked.

Conti and the Ransom Demand

By the spring of 2021, Conti was among the most prolific ransomware operations in the world. Researchers associated it with a Russia-based criminal group often tracked as Wizard Spider, and its structure resembled the ransomware-as-a-service model described in the opening chapter: a core team building the malware and running the leak site, affiliates conducting the intrusions, revenue split between them. Conti practiced double extortion as a matter of routine — encrypt the systems, steal the data, and charge for both the key and the silence. The blockchain analysis firm Chainalysis would later estimate that Conti extorted at least $180 million from victims in 2021, more than any other strain that year.

Conti attacked healthcare routinely. On May 20, 2021 — six days after the HSE attack — the FBI issued an alert stating that Conti had been identified in at least sixteen attacks on healthcare and first-responder networks in the United States within the previous year. The same week, the DarkSide attack on Colonial Pipeline had shut down fuel supplies along the American East Coast and put ransomware, briefly, at the top of the geopolitical agenda.

The HSE's ransom note led to a darkweb negotiation portal, where the demand was posted: $19,999,000. The Irish government's answer came within hours and in public: Taoiseach Micheál Martin — the prime minister — said that no ransom would be paid.

The Decryption Key

On May 20, the attackers posted a working decryption key in the negotiation chat, free of charge.

No explanation accompanied it, and none has ever been established. Speculation at the time ran from the pressure generated by Colonial Pipeline — Western governments were suddenly treating ransomware as a national-security matter — to the reputational cost of shutting down a national health service in the middle of a pandemic. Conti kept the second half of its leverage: the group claimed to have exfiltrated roughly 700 gigabytes of data, including patient information, and continued to threaten its sale or publication unless the twenty million was paid. The extortion now rested on the privacy of patients rather than the availability of systems — an institutional version of the crime examined in the chapter on Vastaamo.

On the same day the key appeared, the HSE obtained an injunction from the High Court against "persons unknown," restraining any sharing, processing, or publication of the stolen data — an order aimed less at the attackers, who were beyond its reach, than at everyone else: journalists, brokers, and platforms through whom the data might travel. The HSE later pursued orders requiring Google's VirusTotal service to help identify who had uploaded and downloaded samples of the stolen files. Files relating to 520 patients surfaced online within two weeks of the attack. But no mass publication ever followed, and the ransom was never paid. Establishing exactly whose data had been taken took years of forensic reconstruction; the HSE eventually wrote to tens of thousands of affected individuals, and in late 2025 it began offering standard payments of 750 euros to people whose personal information had been compromised, alongside the individual claims working through the courts.

The Recovery

The HSE had the key in hand within a week of the attack, and the last systems were not restored until around September 2021 — four months later.

The key itself had to be treated as hostile until proven otherwise: tested, validated with security firms, wrapped in tooling that could be trusted not to make matters worse. Decryption at scale is slow and unreliable — some systems decrypt cleanly; others corrupt, or cost more to recover than to rebuild. And nothing could simply be switched back on, because every machine on the network had been exposed to the intruders for eight weeks; each one had to be verified clean or rebuilt before it could be trusted again. The HSE was doing this across thousands of servers and tens of thousands of devices, with help from private contractors, the National Cyber Security Centre — itself an organization of roughly twenty-five people with an annual budget around five million euros, whose director's post stood vacant at the time of the attack — and personnel from the Defence Forces. By mid-July, around four-fifths of servers and devices were back. Full restoration ran into September.

Throughout those months the health service ran degraded. Outpatient clinics canceled appointments in bulk; diagnostics backed up; referrals to cancer clinical trials were reported to have fallen by some 85 percent during the outage. As with WannaCry, no deaths were officially attributed to the attack; measuring clinical harm through systems that were themselves down is close to impossible — a question taken up in the chapter on ransomware and patient deaths. The direct cost of the response ran on the order of 100 million euros. Paul Reid, the HSE's chief executive, put the eventual bill — including the modernization the attack had made unavoidable — at several times that, with estimates reaching toward half a billion euros.

The Report

The HSE board commissioned an independent post-incident review from PwC and, on December 10, 2021, published it in full: a long, specific, unflattering document laying out the anatomy of the failure, with the HSE's own name on every finding.

The report found that the HSE had no chief information security officer, and no single executive owner of cyber risk at all. Its dedicated cybersecurity staff numbered roughly fifteen people, serving an organization of 130,000. The estate included on the order of 30,000 machines still running Windows 7, out of support and unpatched. The National Healthcare Network was flat, built for connection rather than containment. The report described a low level of cybersecurity maturity across the organization and noted that many of the weaknesses were known and documented before the attack, raised in audits and assessments that produced paperwork but not remediation. The intrusion had used well-known tools and techniques, nothing exotic, and could have been detected and stopped at multiple points across its eight weeks.

Organizations that suffer breaches of this magnitude rarely publish detailed accounts. The usual practice, shaped by litigation and reputation management, is the minimum disclosure the law requires; fuller accounts, when they emerge, tend to be extracted under oath, as in the congressional hearings on Change Healthcare. The HSE did the opposite. The PwC report became, almost immediately, a teaching document for the global health sector: the U.S. Department of Health and Human Services distilled it into a briefing circulated to American hospitals, security teams used it to argue budgets before their own boards, and it remains one of the most cited post-incident reviews in any industry.

Lessons

The free decryption key is the best-remembered detail of the attack. The recovery timeline, the governance findings, and the published report carry most of its lessons.

Ireland held a working decryption key within six days of the attack and still needed four months to restore its systems. A free decryptor is not recovery. The long pole in ransomware recovery is trust: every machine the attacker could have touched must be verified or rebuilt before it can rejoin the network, and in a compromised estate that is every machine. Organizations that plan for ransomware by asking "how would we get a key?" are planning for the short pole. What determines recovery time is the ability to rebuild at scale — images, inventories, clean backups, and hands.

The Irish government could say no to the ransom within hours because a sovereign state operating a public health system can absorb months of disruption on public shoulders and answer for it in a parliament. A private company watching its cash flow die, as in the opening chapter, faces the same demand with none of that ballast. Refusing to pay is a policy only when someone can carry its cost, and sector-wide expectations of refusal get built through backup capacity and public support, not declared by fiat. Ireland's refusal held: no money moved, the data was never mass-published, and the state wore the cost in the open. What refusal actually buys, and what it costs when the data is published anyway, is the subject of the chapter on Medibank.

A published post-mortem converts one country's disaster into everyone's education. The PwC report has been cited in budgets and board papers ever since, likely making other organizations' failures less probable than they would otherwise have been. Whether it prevented more harm worldwide than the attack caused in Ireland cannot be proven, but no other artifact of May 2021 has traveled further. The transparency handed ammunition to litigants and critics, and the HSE published anyway — a choice most breached organizations, shielded by litigation and reputation management, do not make.

Underinvestment in security is usually described in vague percentages; the HSE gave it a headcount. Fifteen cybersecurity staff served a 130,000-person organization holding the health records of a nation, a number visible in every budget cycle alongside the missing CISO and the absent executive owner. Cyber risk had not reached the board's agenda until the morning it was the only item on it. The lesson is governance more than money: an organization that has not assigned ownership of a risk has, by default, accepted it.

The HSE's tooling detected Cobalt Strike seven weeks before detonation and was configured not to block it. Hospitals saw the attacker days before the end and the signal never left the building. The Department of Health, facing the same adversary on the same night, detected and stopped the ransomware. Detection technology was present in both places; a working path from alert to action existed in only one. That gap — visibility without a response plan behind it — is among the more common failure modes in the sector, and this incident documents it cleanly.

The lessons were already published; they were WannaCry's. A flat network, a legacy Windows estate, warnings issued without enforcement, and salvation-by-paper — every structural feature of the Irish disaster had been catalogued in the National Audit Office's anatomy of the NHS's, four years earlier and one island away. Ireland's health service burned on fuel the field had already inventoried.

Conti itself did not long outlive its most famous victim. In February 2022 the group declared its support for Russia's invasion of Ukraine, and within days a Ukrainian security researcher who had gained access to the group's systems leaked tens of thousands of its internal chat messages — revealing salaries, HR complaints, and office politics, a criminal enterprise organized like the mid-sized software company it functionally was. The brand dissolved by mid-2022, its personnel dispersing into successor groups; the United States posted rewards of up to ten million dollars for information on its leaders, and American and British sanctions later named individual members. Gardaí, Ireland's police, seized web domains used in the attack and said the operation had disrupted hundreds of further attempted infections. No one has answered in court for May 14, 2021. The attackers' infrastructure, brand, and chat logs have all passed into history. What endures is the report — the plain, complete, self-incriminating account of how a modern state lost 80 percent of its health service's systems to a spreadsheet. Every health system on earth was offered, free of charge, the education Ireland bought for a hundred million euros. The only question the document cannot answer is how many of its readers believed it applied to them.