Healthcare · India · November 2022
AIIMS Delhi Ransomware Attack
In November 2022, a ransomware attack on the All India Institute of Medical Sciences (AIIMS) in Delhi crippled one of India's premier hospitals for around two weeks, forcing a return to manual operations and becoming a landmark healthcare cyber incident in India.
What happened
In late November 2022, the All India Institute of Medical Sciences in Delhi — one of India's most prestigious and busiest public hospitals — was hit by a ransomware attack that brought its digital operations to a halt. AIIMS Delhi handles enormous patient volumes and treats high-profile individuals, which made the attack both a serious operational crisis and a national security concern.
The attack encrypted key servers and took down the hospital's main digital systems, including those used for patient registration, appointments, billing, and laboratory reports. With those systems unavailable, AIIMS was forced to revert to manual, paper-based processes across its outpatient and inpatient services.
Indian authorities, including national cyber agencies, were drawn into the response. The specifics of the entry point and the group responsible were not fully disclosed publicly, but the scale of the disruption made it one of the defining Indian cyber incidents of the year.
The impact
The operational impact was felt by enormous numbers of patients. AIIMS Delhi serves huge daily volumes, and with digital registration, appointment, and reporting systems down, patients and staff faced long manual queues and delays across the hospital. Sample collection, report generation, and billing all reverted to paper for an extended period.
The data-exposure dimension was especially sensitive. Reporting indicated that the data of a very large number of patients — potentially millions, and reportedly including prominent public figures — may have been compromised, raising national concerns about privacy and the security of health data held by public institutions.
For a flagship public hospital, the reputational and policy impact was significant. The incident became a catalyst for a broader push to strengthen cybersecurity across India's healthcare and public-sector institutions.
How the attack unfolded
- Initial access: the precise entry vector was not fully disclosed publicly.
- Escalation: attackers reached and encrypted core hospital servers.
- Data exposure: a large volume of patient data was reportedly at risk of compromise.
- Impact: main digital systems went down, forcing roughly two weeks of manual operations.
The recovery
AIIMS restored systems over a period of roughly two weeks, sanitizing and rebuilding servers and bringing services back in phases, with some effects lingering beyond the initial restoration.
The lengthy recovery for a major public hospital highlighted the gap between the criticality of healthcare systems and the resilience measures in place to protect them — a gap the incident pushed policymakers to address.
How this attack could have been contained
AIIMS illustrates a universal healthcare truth that crosses borders: when core systems are encrypted, a hospital reverts to paper and patients wait. Immune's self-healing recovery from validated, immutable backups is designed specifically to compress that downtime — restoring registration, reporting, and clinical systems in a controlled order rather than over weeks of manual work.
The reported exposure of a very large volume of patient data points to attacker dwell time and exfiltration before impact. Immune's network monitoring, deception, and access verification target that quiet phase, aiming to catch the intrusion before data leaves and encryption begins.
And because Immune operates at the network level as well as the host, it is designed to protect the mixed, device-heavy environments typical of large public hospitals — including the legacy and connected systems that endpoint tools cannot cover.
Sources
Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.
Related incidents
More ransomware attacks
The February 2024 ransomware attack on Change Healthcare disrupted medical claims and payments nationwide, affecting an estimated 100 million people and becoming one of the costliest healthcare cyberattacks on record.
In May 2017, the WannaCry ransomware worm swept through unpatched systems worldwide and hit the UK's NHS especially hard, reportedly cancelling around 19,000 appointments and becoming a landmark healthcare ransomware event.
Protect against attacks like this
How to defend against healthcare ransomware
Don't let an attack become a shutdown
See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.
