Case file · IRISH HSE 2021

How the HSE cyber attack happened: one spreadsheet and 8 weeks of ignored alerts

Published 2026-09-29 · 4 min read · Missing control: Act on security alerts promptly

Ireland's national health service was knocked back to pen and paper in May 2021 by an attack that had been inside its network for 8 weeks, and that set off security warnings along the way.[1][3] It started with one spreadsheet attached to a phishing email. This case file covers how the attack unfolded, why the alerts went nowhere, what it cost, and the control that would have cut it short.

What happened

Ireland's Health Service Executive, or HSE, runs the country's public health system, with more than 130,000 staff, over 70,000 computers and about 4,000 locations.[2] On March 16, 2021, a phishing email arrived with a malicious Excel file attached. Two days later, on March 18, a staff member opened it on an HSE workstation, and the attackers had their foothold.[1]

On March 31, the workstation's antivirus spotted the attackers' tools running, but it was set to monitor only, so it recorded the problem and did not block it.[1][5] Through April and early May the intruders quietly spread. On May 7 they reached HSE servers for the first time. On May 10 a hospital noticed malicious activity on a key server, and on May 13 the HSE's security provider emailed to say threats on at least 16 systems, dating back to May 7, had not been dealt with.[1]

Just after midnight on May 14, the attackers set off Conti ransomware, which scrambles files so they cannot be used. About 80 percent of the HSE's IT environment was hit.[1][3] The HSE shut down its systems, clinicians lost access to patient records and scheduling, and staff went back to paper.[3]

How they got in

The door was ordinary: an employee opened a booby-trapped spreadsheet that arrived by email, which let the attackers run their own software on that computer.[1] From there they gathered passwords, moved from machine to machine and eventually reached the servers that ran the network, where they could push ransomware everywhere at once.[1][3]

The environment made that easy. An independent review by PwC found more than 30,000 computers still running Windows 7, which had been out of support since January 2020. The HSE had no chief information security officer, no round-the-clock security operations center watching for threats, and no response playbooks for an attack like this.[1][2] The review rated 25 of 28 key security controls as having high-risk gaps.[2]

How it was caught

It was caught too late, by the ransomware itself. The review found that antivirus did detect the attackers' tools on several occasions, but the alerts were not escalated or acted on.[2][3] Two hospitals spotted suspicious activity before the ransomware went off, but that did not trigger a central response. Two other organizations connected to the HSE network did respond to their alerts and stopped the ransomware from running on their systems.[3]

What it cost

The Conti gang demanded $20 million. The Irish government said no ransom was paid, and within a week the gang handed over a decryption key anyway.[4][5] Even with it, recovery took 4 months: the HSE declared all its servers decrypted on September 21, 2021.[1] In the meantime, appointments were cancelled on a large scale; 31 of 54 acute hospitals cancelled some services.[2]

The attackers also copied about 700 gigabytes of unencrypted data, including patient health information.[3] On May 21, 2021, the High Court granted injunctions barring anyone from sharing, selling or publishing it.[4] By February 2022 the HSE had spent €42 million on the response and expected the total to reach about €100 million.[5]

The missing control

The missing control: acting on security alerts promptly. Warnings that the attackers were inside appeared at least 8 weeks before the ransomware, but no one was assigned to watch them, judge them and respond.

Detection worked; response did not. If the March 31 alert had been treated as an incident, the infected workstation could have been isolated and the attackers pushed out while they still had a single foothold. Even the May alerts left days to cut off servers before the ransomware went off, which is exactly what the 2 organizations that did respond managed to do.[1][3] Setting antivirus to block, not just watch, would have closed the gap further.[5]

What to do in your business

Watch the case
The spreadsheet that shut down Ireland's hospitalsDrops 2026-11-19
Close the same gap

Check your business for this control

The free Heist Control Checklist walks through the controls behind every case on this site in about ten minutes. For ready-made policies, the Policy Pack has five editable templates, and the Insider Threat Kit covers risks from inside your own team.

More patching and monitoring cases

Facts are drawn from court records, government reports, company statements and reputable reporting, listed below. People are named only where they were convicted, pleaded guilty or spoke publicly in an official role.

Sources
  1. Krebs on Security: Inside Ireland's public healthcare ransomware scare
  2. The Stack: PwC's HSE hack post-incident report
  3. U.S. Department of Health and Human Services (HC3): Lessons learned from the HSE cyber attack
  4. Law Society Gazette Ireland: HSE secures injunctions over stolen data
  5. Infosecurity Magazine: Massive ransomware attack could cost Irish health executive €100m