LockBit ransomware group ‘apologizes’ for children’s hospital cyberattack

The Hospital for Sick Children announced on New Year’s Day that it was aware of a statement issued by a ransomware group with an apology and an offer of a free decryptor to restore systems impacted by ransomware.

WHY IT MATTERS

On December 18, 2022, SickKids was hit with ransomware and operations went to “Code Grey,” according to an announcement on the hospital’s website. 

“Clinical teams are currently experiencing delays with retrieving lab and imaging results, which may cause longer wait times for patients and families,” the hospital said on December 22.

Other affected systems included employee timekeeping and pharmacy submissions. 

On December 29, the Toronto hospital announced that nearly half of the affected systems had been restored.

According to Globalnews.ca, the LockBit ransomware group that provides affiliates access to malware for a cut of the ransom profits then issued an apology on the dark web on the last day of the year, which was then posted to Twitter.

In the statement, the ransomware organization allegedly blamed a partner and offered a free decryptor for the hospital to unlock its data.

Even with a ransomware group’s decryptor, healthcare organizations only recover on average about two-thirds of their files, said Chester Wisniewski, a Vancouver-based principal research scientist with Sophos, according to the news report

Affiliates have a tendency to scramble data, he said.

The purpose of LockBit’s now-viral statement could be to discourage other affiliates that might see attacking a children’s hospital as an overstep from defecting to another ransomware group, Wisniewski added.

SickKids posted an additional statement to its website that it was aware of the group’s apology and is analyzing the decryptor. The hospital also said it did not make a ransom payment, and that there is no evidence to date that personal information or personal health information has been impacted. 

Brett Callow, a threat analyst with anti-malware company Emsisoft, told the Canadian newsgroup that there is still the question if the allegedly cut-off LockBit affiliate partner still has the hospital’s data.

A spokesman from the Communications Security Establishment noted in the story that more than 400 healthcare organizations in Canada and the United States have experienced a ransomware attack since March 2020.

THE LARGER TREND

In 2021, the Health Sector Cybersecurity Coordination Center released a 31-page briefing on LockBit, its launch of the LockBit 2.0 affiliate program and its recruiting efforts for its ransomware-as-a-service program.

“The only thing you have to do is to get access to the core server, while LockBit 2.0 will do all the rest,” according to LockBit’s documentation that HC3 had obtained.

Through an interview with a LockBit ransomware operator, the cybersecurity arm of the U.S. Department of Health and Human Services indicated that the cyber gang has a measure of ethics. 

It won’t operate in certain states like Belarus and Russia for having “a contradictory code of ethics,” and may have disdain for those who attack healthcare entities, said HC3.

However, “While threat actors may state publicly that their personal ethics influence their target selection, many adversaries go after the easiest victims regardless of any moral obligation, based on our experience,” according to the briefing.

Healthcare cybersecurity experts encourage the industry to fight cybercrime-as-a-service with security collaboration because lives – like those at SickKids – suffer the diversions of care that inevitably follow ransomware attacks. 

ON THE RECORD

“These attacks can sometimes originate much closer to home than we realize,” Callow told Canadian news. 

“We think the attacks are coming in from Russia or Commonwealth of Independent States countries, whereas in some cases they could be originating from within our own border,” he said, noting that LockBit malware was connected to recent ransomware attacks on two small municipal governments – St. Mary’s, Ontario, and Westmount, Quebec.

Andrea Fox is senior editor of Healthcare IT News.
Email: af**@***ss.org

Healthcare IT News is a HIMSS publication.

Read More
Larisa Paris

Latest

Shenzhen July Live Music Picks

Music ...

Jux – Kipepeo Ft Mbosso

MusicDOWNLOAD MP3 SONG...

Amangisi – Shiya Lomfana

MusicDOWNLOAD MP3 SONG...

Amangisi – Sponsor ft NOSIPHO

MusicDOWNLOAD MP3 SONG...

Newsletter

Don't miss

Shenzhen July Live Music Picks

Music ...

Jux – Kipepeo Ft Mbosso

MusicDOWNLOAD MP3 SONG...

Amangisi – Shiya Lomfana

MusicDOWNLOAD MP3 SONG...

Amangisi – Sponsor ft NOSIPHO

MusicDOWNLOAD MP3 SONG...

Amangisi – Ama-Thousand

MusicDOWNLOAD MP3 SONG...

Bright young business brains bring ideas to life

Friday 17 July, 2026 Young Cumbrian entrepreneurs showed off their innovative business ideas, from AI virtual assistants to African food, at two celebration events this week. Fifteen young people from Furness and West Cumbria aged 14 to 25 were selected to take part in the Positive Enterprise programme back in January...

No, no, no — business travel is not dead. It’s still moving, and rather well at that

Par Bruno COURTIN Published on 7 Aug 2026 - Updated on 7 Aug 2026 3 min reading time According to forecasts from GBTA, the world's leading organisation representing business travel stakeholders, global business travel spending is set to hit a record $1.71 trillion in 2026, while the number of trips is expected to reach 1.84

How AI is changing the business analyst role for the better

By offering the ability to automate routine note-taking, requirements gathering, and data analysis tasks, AI is helping to make the decisive human side of this key business-IT role more impactful. AI’s impact has been felt across nearly every industry, and its rise has already started to alter several roles in tech, including that of the