What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
A ransomware-related cyberattack disrupted emergency admissions at University Hospital Düsseldorf (UKD) in September 2020. An ambulance carrying a critically ill woman was diverted to a hospital in Wuppertal, where she later died. But prosecutors later said they could not establish that the cyberattack caused her death: they believed her injuries were so severe that she likely would have died even if admitted in Düsseldorf.
What happened at University Hospital Düsseldorf?
On September 10, 2020, major parts of UKD’s IT systems became unusable. The hospital said the outage had broad operational effects: it stopped taking emergency patients, postponed planned and outpatient treatments, and asked patients not to attend even if they had appointments. UKD said care for patients already admitted remained assured. UKD’s September 11 update described those effects.
On September 17, UKD confirmed that a hacker attack had exploited a vulnerability in a widely used commercial software add-on. The hospital said systems failed progressively and access to stored data was blocked. At that point, it reported no evidence that data had been irretrievably destroyed or specifically stolen, and no concrete ransom demand. The hospital’s public notice did not name the vulnerable software. UKD’s incident update provides its account.
Recommended Free Tools
A contemporaneous U.S. Department of Health and Human Services presentation listed 30 servers as disabled in a preliminary summary. Golem also reported that 30 servers had been encrypted. This is a reported contemporaneous count, not a final forensic inventory. HHS’s September 24, 2020 presentation gives the figure.
#1 Best Overall
What happened to the patient?
Contemporaneous reporting said an ambulance carrying a woman in a life-threatening condition could not take her to UKD because the hospital was not accepting emergency patients. It diverted her to Wuppertal, about 30 km away, and she died after the transfer. Early reports described treatment as beginning roughly an hour later. The Guardian’s report covered the diversion and death; the distance is also described in an Institute for Peace Research and Security Policy at the University of Hamburg analysis.
Did the cyberattack cause the patient’s death?
That was not established. In November 2020, prosecutor Christoph Hebbecker said the negligent-homicide investigation had been discontinued because investigators could not prove a causal connection between the attack and the death. He also said the patient’s injuries were considered so severe that she likely would have died even if she had been admitted to UKD. Golem reported the prosecutor’s statement.
The distinction matters: the outage disrupted emergency intake, and the patient was diverted before she died, but prosecutors did not conclude that the diversion or attack caused her death. The available account supports reporting the sequence of events, not presenting the attack as a proven cause.
The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →What did the hospital say about its security measures?
In a September 18 update, UKD said it had installed the available patch on the day it was released and had followed guidance from Germany’s Federal Office for Information Security (BSI) and the software vendor. It also said an external penetration test earlier that summer had not identified the vulnerability, and described additional fallback systems. These are the hospital’s statements, not an independent assessment of whether its security was adequate. The September 18 update sets out its account.
Rank #3
The incident illustrates a limit of patching and security testing: applying a patch when it becomes available and conducting a penetration test do not guarantee that every vulnerability will be identified before an attack. UKD’s notices do not establish the precise initial-access timeline or explain the technical failure mode beyond the exploited software vulnerability and progressive system failures.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How long did the disruption last, and who was blamed?
The Institute for Peace Research and Security Policy at the University of Hamburg said essential services and emergency care took nearly two weeks to restore. Its analysis discusses hospital resilience in practical terms, including downtime and interoperability between systems; it does not establish that a particular intervention would have prevented this incident. The institute’s case analysis provides that context.
Rank #4
In March 2023, LKA NRW attributed the extortion of UKD to the DoppelPaymer/DoppelSpider group, also known as Indrik Spider. The agency said investigators had identified group members and sought three suspected leaders under arrest warrants. That is a law-enforcement attribution and description of investigative action, not a report that each suspect was convicted. LKA NRW’s announcement describes the attribution and warrants.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

