Immune — Self Heal, an iStudio Technologies product

Healthcare · India · November 2022

AIIMS Delhi Ransomware Attack

In November 2022, a ransomware attack on the All India Institute of Medical Sciences (AIIMS) in Delhi crippled one of India's premier hospitals for around two weeks, forcing a return to manual operations and becoming a landmark healthcare cyber incident in India.

What happened

In late November 2022, the All India Institute of Medical Sciences in Delhi — one of India's most prestigious and busiest public hospitals — was hit by a ransomware attack that brought its digital operations to a halt. AIIMS Delhi handles enormous patient volumes and treats high-profile individuals, which made the attack both a serious operational crisis and a national security concern.

The attack encrypted key servers and took down the hospital's main digital systems, including those used for patient registration, appointments, billing, and laboratory reports. With those systems unavailable, AIIMS was forced to revert to manual, paper-based processes across its outpatient and inpatient services.

Indian authorities, including national cyber agencies, were drawn into the response. The specifics of the entry point and the group responsible were not fully disclosed publicly, but the scale of the disruption made it one of the defining Indian cyber incidents of the year.

The impact

The operational impact was felt by enormous numbers of patients. AIIMS Delhi serves huge daily volumes, and with digital registration, appointment, and reporting systems down, patients and staff faced long manual queues and delays across the hospital. Sample collection, report generation, and billing all reverted to paper for an extended period.

The data-exposure dimension was especially sensitive. Reporting indicated that the data of a very large number of patients — potentially millions, and reportedly including prominent public figures — may have been compromised, raising national concerns about privacy and the security of health data held by public institutions.

For a flagship public hospital, the reputational and policy impact was significant. The incident became a catalyst for a broader push to strengthen cybersecurity across India's healthcare and public-sector institutions.

How the attack unfolded

  • Initial access: the precise entry vector was not fully disclosed publicly.
  • Escalation: attackers reached and encrypted core hospital servers.
  • Data exposure: a large volume of patient data was reportedly at risk of compromise.
  • Impact: main digital systems went down, forcing roughly two weeks of manual operations.

The recovery

AIIMS restored systems over a period of roughly two weeks, sanitizing and rebuilding servers and bringing services back in phases, with some effects lingering beyond the initial restoration.

The lengthy recovery for a major public hospital highlighted the gap between the criticality of healthcare systems and the resilience measures in place to protect them — a gap the incident pushed policymakers to address.

How this attack could have been contained

AIIMS illustrates a universal healthcare truth that crosses borders: when core systems are encrypted, a hospital reverts to paper and patients wait. Immune's self-healing recovery from validated, immutable backups is designed specifically to compress that downtime — restoring registration, reporting, and clinical systems in a controlled order rather than over weeks of manual work.

The reported exposure of a very large volume of patient data points to attacker dwell time and exfiltration before impact. Immune's network monitoring, deception, and access verification target that quiet phase, aiming to catch the intrusion before data leaves and encryption begins.

And because Immune operates at the network level as well as the host, it is designed to protect the mixed, device-heavy environments typical of large public hospitals — including the legacy and connected systems that endpoint tools cannot cover.

Sources

Figures are drawn from public reporting and official disclosures and are presented as reported or estimated; they may be updated as further details become public.

Protect against attacks like this

How to defend against healthcare ransomware

Don't let an attack become a shutdown

See how Immune detects ransomware in seconds, contains it before it spreads, and self-heals clinical systems from immutable backups.

Talk to us

See Immune protect your organization

Tell us about your environment and our team will show you exactly how Immune detects, contains, and self-heals through a ransomware attack — including the connected devices your current tools can't reach. We respond within one business day.

  • A working demo on a realistic scenario
  • Agentless coverage for medical and connected devices
  • On-premises and data-sovereignty deployment options
  • A frank look at where Immune fits alongside your stack

Request your demo

Tell us a little about your organization and we'll be in touch.

By submitting, you agree to be contacted about Immune. We respect your privacy and never share your details. See our privacy policy.