LockBit affiliates published 1.9 million patient records from a German hospital network on July 21 2026 after breaching systems on July 19. The affected network operates 12 hospitals across North Rhine-Westphalia. The group demanded 12 million euros within 72 hours.
Stolen data includes medical histories, insurance details, and imaging files. No evidence of ransomware encryption has been found yet according to the German Federal Office for Information Security.
The hospitals had migrated to a new electronic health record system in May 2026 that contained unpatched vulnerabilities in third-party integration software.
LockBit has claimed over 4,800 victims since 2022 and remains the most active ransomware group despite law enforcement takedown attempts in 2024 and 2025.
Why this matters
Healthcare remains the most targeted sector for ransomware with average breach costs exceeding 10 million dollars per incident. The attack highlights persistent weaknesses in hospital IT modernization projects.
European health regulators may accelerate mandatory cybersecurity audits under the NIS2 directive starting January 2027.
The hospitals restored operations from backups by July 24 and declined to pay the ransom.