
French healthcare provider Hospital Simone Veil said it won’t give in to the demands of the LockBit ransomware group which breached its internal network earlier this year.
Last month, Cannes-based Hospital Simone Veil ((CHC-SV) said that it was a victim of a cyber attack on February 16. Immediately after identifying the attack, the hospital took steps to contain the impact of the incident, including taking its entire computer network offline, which forced staff to migrate to manual mode of working.
CHC-SV added that as a result of the cyber security incident, it was forced to cancel almost a third of non-emergency operations throughout Tuesday and Wednesday. Also, multiple non-emergency consultations were rescheduled.
Recently, the infamous LockBit ransomware group claimed responsibility for the cyber attack on the healthcare provider and listed CHC-SV as a victim on its data leak site. The group gave a deadline of May 1 for the hospital to meet its ransom demands, failing which it threatened to publish the stolen data.
🚨 #Healthcare #CyberAttack Alert 🚨
— HackManac (@H4ckManac) April 30, 2024
The LockBit 3.0 ransomware group claims responsibility for the attack on Cannes Hospital (Hôpital de Cannes Simone Veil).
The hospital reported on April 16th that it had fallen victim to a cyberattack, causing severe disruptions.… https://t.co/jnQ1m71lDq pic.twitter.com/4en7kSLDPx
Hospital Simone Veil has, however, announced on X that it won’t pay any ransom demanded by the hacker group and has notified the Gendarmerie and the National Agency for Information Systems Security (ANSSI) about the demand.
“In the case of a publication of data potentially belonging to the hospital, we will communicate to our patients and our stakeholders, at the end of the detailed examination of the files which may have been exfiltrated, on the nature of the stolen information,” reads CHC-SV’s post on X.
❗️Communiqué de presse
— Hôpital de Cannes Simone Veil CHC-SV (@hopitaldecannes) May 2, 2024
Le centre hospitalier de Cannes Simone Veil confirme que les données publiées dans la soirée du 1er mai lui appartiennent.
The healthcare provider added that it is still in the process of restoring the affected systems to get back to normal operation as soon as possible. Also, its IT team is working closely with relevant authorities and cyber security experts to resolve the matter at the earliest.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543