Case study
Rhysida encrypts a specialty hospital's PACS and HIS servers
A hospital's PACS imaging server, its attached NAS imaging volume and the HIS application server were encrypted by Rhysida over a holiday night, with .rhysida appended and the operators threatening to publish patient images. Build analysis showed the free decryptor applied to part of the file set; the remaining images came from modality caches and an offline drive, HIS was restored from an offline dump, and no ransom was paid.
- Industry
- Healthcare Ransomware Response and Recovery
- Family
- Rhysida
- Scenario
- File Server Encrypted
- Handled
- 2026-02
This case study is composed from typical scenarios to illustrate our approach and the recovery paths involved. It does not describe a specific customer incident; real cases involving customer data are published only with authorization.
约 97%
Imaging data recovered
约 62%
Files covered by the free decryptor
约 30 小时
Core clinical chain restored
0
Ransom paid
Incident background
The client is a private specialty hospital whose revenue comes mainly from imaging. PACS storage ran on a Windows server, its imaging volume mounted over iSCSI from a NAS in the same room; HIS application and database ran on two further servers, and a nightly backup job wrote to a share on that same NAS.
The only offline practice was a duty engineer copying the HIS database dump to an external drive each day and unplugging it; imaging was too large for that routine and was copied by hand only occasionally - most recently three weeks earlier. The imaging vendor had long used one shared VPN account for remote maintenance, with no multi-factor authentication and a password unchanged for years; once connected it reached the imaging and HIS segments directly. Outpatient, diagnostic and administrative areas were not segmented.
On the third night of the holiday, the duty technician found workstations could not retrieve the day's studies and the PACS service would not start. Files on the imaging volume and in the HIS data directories had .rhysida appended to their full original names, and every directory level held an English ransom note, CriticalBreachDetected.pdf, carrying a per-victim code and a Tor portal address but no email contact. The NAS backup share was encrypted as well, and its snapshot job had been disabled before the event.
Before calling us, duty staff had rebooted the PACS server once and reinstalled two imaging workstations.
What we did
Containment went out on the first call: affected servers and the NAS powered but off the network, every VPN account disabled, writes and backup jobs halted, and no reboot, reinstall or decryptor run.
- Evidence and imaging. Read-only images of the PACS system disk, the NAS imaging volume and the HIS data disks, plus VPN, firewall and security logs; samples and the original note were preserved, and later work ran on copies.
- Family confirmation and recoverability. The extension and note identified the Rhysida Windows encryptor, not the ESXi variant, and reversing the key-generation routine put the build inside the publicly disclosed flaw range. Because that route depends on estimating when each file was encrypted, files whose timing evidence the reboot and reinstalls had disturbed failed verification on copies; only batches that passed went to bulk decryption.
- Recovery. Decryptable files were processed in batches with DICOM integrity checked series by series; the rest came from CT, MR and DR modality caches and the offline drive. The image library and HIS were rebuilt on clean servers, HIS from the offline dump, then reconciled against audit logs.
- Hardening in parallel. Vendor access moved behind a jump host with per-person accounts and enforced MFA, imaging and HIS segments split from the office network, rogue accounts and persistence removed, credentials reset, and backups moved to a dedicated host with immutable copies.
- Deliverables. Incident report, recovery manifest with verification records, exfiltration scope determination, and hardening checklist.
Recovery result
About 97% of imaging data was recovered: the free decryptor covered roughly 62% of the encrypted image files, and the rest was rebuilt from modality caches and the offline drive. The residual 3% were studies from the last three weeks that sat outside the offline copy and had rolled out of the caches; these were unrecoverable and were re-registered from paper reports and film. HIS was restored to the previous day's offline dump, and about 11 hours of registration, billing and order records were re-entered from paper documents.
From remote access to a working register-consult-order-bill chain took about 30 hours, and full imaging reconciliation completed within four business days. No ransom was paid and the portal was never contacted.
Forensics showed entry through the shared vendor VPN account with no MFA, a dwell of around nine days, spread to the imaging and HIS segments via credential dumping, and detonation on a holiday night after shadow copies were deleted and backup jobs disabled. Egress records indicated tens of gigabytes of images and patient index data had already been exfiltrated. Using our exfiltration scope determination, the hospital completed internal notification, reporting to the competent authorities and notice to affected patients under the applicable personal information protection and incident reporting requirements. We recommended offsite immutable imaging archives.
This is an illustrative case compiled from typical scenarios and anonymized; it does not refer to any specific client.
Emergency response
Data already encrypted? Stop and let an engineer look first
We do not pay ransoms and we do not negotiate with attackers. Engineers run a free assessment first, then propose a recovery plan and a firm quote.
Related content
File Servers and NAS Encrypted by Ransomware
When shared folders on a file server or NAS are encrypted, drawings, contracts, archives, quotations and design sources all become unusable at once — and mapped drives spread the impact to every endpoint. This page covers how to gauge spread, what shadow copies and snapshots realistically offer, and how to sequence recovery by business value.
Healthcare Ransomware Response and Recovery
When a hospital is hit, registration, consultation, orders, billing, laboratory and imaging fail at the same moment and care falls back to paper. This page covers the healthcare threat picture, a recovery priority built around clinical continuity, and the handling of patient data and compliance obligations.
- Some versions decryptable
Rhysida
Rhysida is a RaaS operation active since 2023, marked by the .rhysida extension and a CriticalBreachDetected.pdf ransom note. It hits healthcare, education, manufacturing and government, ships an ESXi encryptor, and a subset of early Windows samples can be recovered with a free decryptor.