Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In late April 2023, German health-insurance IT provider BITMARCK said its early-warning systems had detected an attack on internal systems. It took systems offline as a precaution, disrupting services used by connected statutory health insurers and their customers. The public reporting reviewed at the time did not establish the attack method, whether ransomware was involved, or a final restoration date for every affected service.

What happened when BITMARCK took systems offline?

BITMARCK said its early-warning systems detected an attack on internal systems in spring 2023. The company shut down systems as a preventive measure while it responded. In its later account, BITMARCK said it had identified and successfully defended against the cyberattack, while acknowledging that its response left connected insurers and their customers facing significant restrictions for an extended period.

BITMARCK provides software and IT services to Germany’s statutory health-insurance sector. The company currently says more than 80 percent of the country’s statutory health-insurance funds are customers, and that around 25 million members benefit from its solutions. Those are BITMARCK’s present-day company figures, not a count of insurers or people confirmed to have been affected by the 2023 incident.

How were insurers and their customers affected?

The disruption was visible in services that depend on data exchange between insurers and healthcare providers. KNAPPSCHAFT, one BITMARCK customer, said the incident restricted its data exchange with hospitals, rehabilitation clinics and care services. It also reported effects on issuing new health cards.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

KNAPPSCHAFT said its electronic sick-leave certificates (eAU) and electronic treatment and cost plans (eHKP) were not affected. Members could still contact the insurer by phone, post, in person or through its app. These details describe KNAPPSCHAFT’s own services, not every BITMARCK customer.

In an early-May 2023 snapshot, SecurityWeek reported that restoration work was underway for systems used in eAU, electronic patient-file access (ePA), internal insurer services and payment-related processes. Restoration was gradual, and disruptions could continue as systems were brought back online in a security- and priority-oriented process. That report describes the situation at the time; it is not a current status report.

Was the April 2023 BITMARCK attack ransomware?

The reviewed public reporting did not identify the attacker or establish the attack type. SecurityWeek said BITMARCK had not disclosed the nature of the attack and reported that it was unclear whether ransomware or another kind of attack had caused the disruption. Calling this a confirmed ransomware attack would therefore go beyond what those sources established.

BITMARCK’s shutdown was a containment and precautionary response, but the available accounts do not specify whether an attacker executed a payload or provide a detailed technical account of the incident. The company’s later description that it successfully defended against the attack does not, by itself, fill in those technical details.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the spring shutdown differs from BITMARCK’s January 2023 incident

The April shutdown should not be conflated with a separate unauthorized-access incident that BITMARCK disclosed in February 2023. The earlier event involved stolen credentials and reported data exfiltration; the spring event is documented primarily as a precautionary shutdown that disrupted operations.

Incident What the sources say Reported impact
January 2023 unauthorized access, disclosed in February BITMARCK said its Cyber Defence Team detected access to part of its IT infrastructure using stolen credentials on 19 January. Its February disclosure said an analysis found fragmented insured-person records among material taken. BITMARCK said health-data core systems and telematics infrastructure were not affected in this incident. Tagesschau reported that data from around 300,000 online customers of various insurers was involved. This figure concerns the January incident, not the April shutdown.
Spring 2023 cyberattack and shutdown BITMARCK said its early-warning systems detected an attack on internal systems in late April and that it took systems offline as a precaution. The public reporting reviewed did not establish the attack type or whether data was stolen. Connected insurers and customers experienced operational restrictions, including the service interruptions KNAPPSCHAFT described. The January incident’s data findings do not establish what happened to data during the spring attack.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What is known about recovery?

SecurityWeek reported in early May that restoration work had begun and that services were being brought back in stages. BITMARCK later characterized the attack as successfully defended against. The available sources do not give a complete service-by-service restoration timeline or a final date on which every affected service returned to normal.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.