Case File

The Düsseldorf University Hospital Ransomware Attack 2020

Cyberangreb på tysk universitetshospital førte til død og internationale efterforskning

🇩🇪 German

Published May 7, 2026

Ransomware-Angriff Uniklinik Düsseldorf 2020
EVIDENCE

Quick Facts

Perpetrator(s)Not publicly identified – linked to the DoppelPaymer group
Victim(s)KrimiNyt has chosen not to publish the victim's name
Crime sceneUniversitätsklinikum Düsseldorf, Düsseldorf, North Rhine-Westphalia, Germany
Date of crime10 September 2020
Type of crimeRansomware attack on critical infrastructure; investigation for negligent homicide

The Attack on Universitätsklinikum Düsseldorf

On September 10, 2020, Universitätsklinikum Düsseldorf (UKD), one of the Rhineland's leading university hospitals, was subjected to a massive ransomware attack. The attack was later attributed to the cybercriminal group Netwalker, known for targeting organizations with high financial capacity to pay ransoms. The attack presented Germany with an unprecedented security crisis within the healthcare sector and drew attention from both national and international security authorities.

The Course and Cost of the Attack

Timeline

10 September 2020

78-year-old woman redirected to hospital in Wuppertal and dies

A 78-year-old woman seeking emergency treatment is sent to Wuppertal instead of the nearby UKD. She subsequently dies as a result of her condition.

10 September 2020

78-year-old woman redirected to hospital in Wuppertal and dies

A 78-year-old woman seeking emergency treatment is sent to Wuppertal instead of the nearby UKD. She subsequently dies as a result of her condition.

17 September 2020

BSI confirms attack and cooperates with authorities

The German cybersecurity authority BSI issues a press release on September 17, 2020, confirming the technical circumstances of the case and cooperation between authorities.

18 September 2020

International media cover police homicide investigation

The New York Times and Deutsche Welle report on September 18, 2020, on Düsseldorf police opening an investigation on suspicion of negligent homicide.

1 January 2020

Negligent homicide investigation closed without charges

Prosecutors conclude that a sufficient causal connection between the cyberattack and the woman's death cannot be established. The case is closed without charges being brought.

Hackers infiltrated the hospital's IT systems and encrypted critical data. As with a typical ransomware attack, the perpetrators demanded a ransom—in this case approximately 19 million Danish kroner—in exchange for decrypting the systems. The hospital was forced to shut down parts of its operational capacity, as doctors and nurses could not access electronic patient records and other vital medical systems.

Particularly tragic about the attack was that it had direct consequences for patient care. A 78-year-old woman who was scheduled to undergo cancer treatment was turned away and died shortly thereafter from a stroke. Although no direct causal link could be established, her death was nonetheless connected to the attack in media coverage, and questions were raised about the hospital's crisis management and preparedness for handling cyberattacks.

Response and Investigation

The BSI and German cybersecurity authorities were called in to assist with system recovery. Cyberattacks on the healthcare sector quickly became a priority investigation. The attack drew political interest at the highest level, as it revealed Germany's vulnerability to cyberterrorism targeting critical infrastructure.

The Netwalker group, which claimed responsibility, was previously known for attacking companies worldwide. The group typically operated by stealing sensitive data before encryption—a double extortion tactic in which they threatened to publicly release data if the ransom was not paid. UKD was therefore under double pressure: both system restoration and data protection.

Security Implications

The attack on UKD became a wake-up call for both German and European critical infrastructure. The hospital had followed standard cybersecurity procedures, but the hackers were sophisticated enough to bypass them. Ransomware attacks on hospitals subsequently became the subject of intensive focus from security authorities.

Bundesamt für Sicherheit in der Informationstechnik (BSI), Germany's national cybersecurity agency, established increased monitoring of healthcare institutions. Danish CFCS and other European security bodies began sharing intelligence about Netwalker group activities.

Legal Follow-up

In the years following the attack, several individuals linked to the Netwalker group were identified and charged in various countries. The attack did not result in convictions directly tied specifically to the UKD attack, but it contributed to international efforts against organized cybercrime.

The German Justice Ministry used the case as evidence for the need for stricter cybersecurity legislation and increased resources for digital investigation. In 2021, new guidelines were introduced for the protection of critical infrastructure in Germany.

Aftermath

The 2020 UKD attack remains one of the most serious cyberattacks on European healthcare and serves as a historical example of the ransomware threat to critical infrastructure. The hospital eventually restored its systems, but the attack left deep marks on the debate about digitalization, cybersecurity, and the state's responsibility for protecting essential societal functions.

The case also illustrates an important legal complexity: even when perpetrators are identified (as with the Netwalker group), prosecution can be difficult when they operate from jurisdictions without extradition agreements with Western countries. This became a central theme in international cybersecurity cooperation after 2020.

Ask about this case

Answers from KrimiNyt's coverage only

Follow this case

Get an email when a new documentary, podcast or book about The Düsseldorf University Hospital Ransomware Attack 2020 appears, or when a verdict is reached.

Share this post: