The Düsseldorf University Hospital Ransomware Attack 2020
Cyberangreb på tysk universitetshospital førte til død og internationale efterforskning
Published May 7, 2026

Quick Facts
The Attack on Universitätsklinikum Düsseldorf
On September 10, 2020, Universitätsklinikum Düsseldorf (UKD), one of the Rhineland's leading university hospitals, was subjected to a massive ransomware attack. The attack was later attributed to the cybercriminal group Netwalker, known for targeting organizations with high financial capacity to pay ransoms. The attack presented Germany with an unprecedented security crisis within the healthcare sector and drew attention from both national and international security authorities.
The Course and Cost of the Attack
Timeline
78-year-old woman redirected to hospital in Wuppertal and dies
A 78-year-old woman seeking emergency treatment is sent to Wuppertal instead of the nearby UKD. She subsequently dies as a result of her condition.
78-year-old woman redirected to hospital in Wuppertal and dies
A 78-year-old woman seeking emergency treatment is sent to Wuppertal instead of the nearby UKD. She subsequently dies as a result of her condition.
BSI confirms attack and cooperates with authorities
The German cybersecurity authority BSI issues a press release on September 17, 2020, confirming the technical circumstances of the case and cooperation between authorities.
International media cover police homicide investigation
The New York Times and Deutsche Welle report on September 18, 2020, on Düsseldorf police opening an investigation on suspicion of negligent homicide.
Negligent homicide investigation closed without charges
Prosecutors conclude that a sufficient causal connection between the cyberattack and the woman's death cannot be established. The case is closed without charges being brought.
Hackers infiltrated the hospital's IT systems and encrypted critical data. As with a typical ransomware attack, the perpetrators demanded a ransom—in this case approximately 19 million Danish kroner—in exchange for decrypting the systems. The hospital was forced to shut down parts of its operational capacity, as doctors and nurses could not access electronic patient records and other vital medical systems.
Particularly tragic about the attack was that it had direct consequences for patient care. A 78-year-old woman who was scheduled to undergo cancer treatment was turned away and died shortly thereafter from a stroke. Although no direct causal link could be established, her death was nonetheless connected to the attack in media coverage, and questions were raised about the hospital's crisis management and preparedness for handling cyberattacks.
Response and Investigation
The BSI and German cybersecurity authorities were called in to assist with system recovery. Cyberattacks on the healthcare sector quickly became a priority investigation. The attack drew political interest at the highest level, as it revealed Germany's vulnerability to cyberterrorism targeting critical infrastructure.
The Netwalker group, which claimed responsibility, was previously known for attacking companies worldwide. The group typically operated by stealing sensitive data before encryption—a double extortion tactic in which they threatened to publicly release data if the ransom was not paid. UKD was therefore under double pressure: both system restoration and data protection.
Security Implications
The attack on UKD became a wake-up call for both German and European critical infrastructure. The hospital had followed standard cybersecurity procedures, but the hackers were sophisticated enough to bypass them. Ransomware attacks on hospitals subsequently became the subject of intensive focus from security authorities.
Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany's national cybersecurity agency, established increased monitoring of healthcare institutions. Danish CFCS and other European security bodies began sharing intelligence about Netwalker group activities.
Legal Follow-up
In the years following the attack, several individuals linked to the Netwalker group were identified and charged in various countries. The attack did not result in convictions directly tied specifically to the UKD attack, but it contributed to international efforts against organized cybercrime.
The German Justice Ministry used the case as evidence for the need for stricter cybersecurity legislation and increased resources for digital investigation. In 2021, new guidelines were introduced for the protection of critical infrastructure in Germany.
Aftermath
The 2020 UKD attack remains one of the most serious cyberattacks on European healthcare and serves as a historical example of the ransomware threat to critical infrastructure. The hospital eventually restored its systems, but the attack left deep marks on the debate about digitalization, cybersecurity, and the state's responsibility for protecting essential societal functions.
The case also illustrates an important legal complexity: even when perpetrators are identified (as with the Netwalker group), prosecution can be difficult when they operate from jurisdictions without extradition agreements with Western countries. This became a central theme in international cybersecurity cooperation after 2020.
Ask about this case
Answers from KrimiNyt's coverage onlyFollow this case
Get an email when a new documentary, podcast or book about The Düsseldorf University Hospital Ransomware Attack 2020 appears, or when a verdict is reached.


