Yes. Ireland obtained a decryptor after the Conti ransomware attack on its Health Service Executive (HSE) in May 2021, but officials tested it before use because they feared it might be flawed or cause further harm. The tool was later reported to be genuine and functional, yet flawed; restoring the HSE’s systems was still expected to take many weeks. Ireland said it would not pay the reported $20 million ransom.
What happened to Ireland’s HSE?
A ransomware attack disrupted the public health service
In May 2021, the HSE, Ireland’s public health system, was hit by Conti ransomware. CyberScoop described the HSE as a $25 billion public health system in its 2021 coverage. The shutdown of its IT systems affected work across maternity care, radiology, diagnostics, patient administration, chemotherapy and radiation oncology.
Did Ireland get a decryption key, and was it safe?
Officials tested the tool before relying on it
Officials had obtained a decryption tool, but did not treat possession of it as proof that systems could safely be restored. The Irish government said the National Cyber Security Centre (NCSC) and private contractors were carrying out a technical process to check the tool’s integrity and ensure it would restore systems rather than cause further harm.
The Irish Times later reported that the tool was verified as genuine and functional, but officials considered it flawed. They also worried that software supplied by the Russian-speaking criminals could include backdoors that would enable further attacks. A working decryptor therefore did not remove the need to assess its safety or rebuild and restore affected systems.
#1 Best Overall
Why did recovery take so long?
Decrypting files was only one part of restoration
The HSE warned that restoration would take “many weeks” and that major disruption would continue because its IT systems had been shut down. Officials expected early signs of recovery at some sites over the days that followed, but that was not a promise of a full or rapid return to normal. As Prime Minister Micheál Martin put it, obtaining the tool “doesn’t really take away from the enormous work that still lies ahead in terms of the rebuilding of the systems overall.”
In practice, a health service cannot resume clinical work simply because a decryptor exists: officials must establish that restoration will not damage systems further, then bring disrupted services back online. The HSE’s warning reflected that wider recovery effort, not just the time needed to run a decryption tool.
Rank #2
Care continued, but access was sharply constrained
Emergency departments continued operating, while people seeking non-urgent care were warned to expect long delays. Irish health officials reported that medical appointments fell by as much as 80% in parts of Ireland after the breach; this was a reported local maximum, not a nationwide figure for every service. The disruption reached clinically important workflows, including diagnostics and cancer treatment services.
Recovery required outside support
Ireland’s response involved the NCSC, private contractors, FireEye and McAfee. CyberScoop also reported that Ireland shared intrusion data with the European Union. These organizations supported the response and recovery; their involvement did not make restoration immediate.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Did Ireland pay the ransom?
The government refused the reported demand
Prime Minister Micheál Martin said Ireland would not pay the reported $20 million ransom. The Irish Times reported the equivalent demand as €16.7 million. Lindy Cameron, then head of the UK National Cyber Security Centre, assessed that supplying a decryptor could be a public-relations move intended to “lessen criticism.” She warned that successful ransomware payments can encourage criminals to repeat the model: “It’s important that we do all we can to ensure this is not a criminal model that yields returns.”
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What is known about patient-data exposure?
The CyberScoop and Irish Times accounts described here focus on the service outage, decryptor and recovery response; they do not establish whether patient data was exfiltrated or published. Service disruption and data theft are distinct risks, so the reported appointment impact should not be taken as evidence either way about exposure of records.
Quick Recap
Rank #4
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

