Cyber-attack Timeline: AIIMS

Educational & easy-to consume visual guides to understanding attacks & enhancing resilience

AIIMS Report Image AIIMS Timeline Image-1

Download Our Educational Cyber Attack Timeline on the AIIMS Ransomware Attack

At Cyber Management Alliance, Incident Response and Ransomware Mitigation is our passion. We study and analyse cyber-attacks and ransomware attacks to create informational visual timelines which can be easily read for educational purposes and to enhance cyber resilience.

For the AIIMS Ransomware Attack, we have created a visual timeline and an accompanying detailed report.  Download it now. 

Read our blog on AIIMS Ransomware Attack.

Disclaimer: This document has been created with the sole purpose of encouraging discourse on the subject of cybersecurity and good security practices. Our intention is not to defame any company, person or legal entity. Every piece of information mentioned herein is based on reports and data freely available online. Cyber Management Alliance neither takes credit nor any responsibility for the accuracy of any source or information shared herein.

  • ** GDPR ** We wholeheartedly believe your and our rights to privacy and in the GDPR. The bottom of the page explains how we use your data. 
  • Align with the GDPR requirements.
  • Increase your Breach Readiness.
  • Reduce your time to detect and respond.

Complete the form below to receive a copy of the detailed AIIMS attack document and timeline.

cyber-essentials-certification
NCSC Certified Training B&W 300px
CSC

FAQs on the AIIMS Cyber Attack

  • What happened in the AIIMS Delhi cyber attack?

    On 23 November 2022, the All India Institute of Medical Sciences (AIIMS) Delhi — India’s premier public hospital and medical research institute — was hit by a ransomware attack that took down the National Informatics Centre’s eHospital service and forced staff to run patient care manually for around two weeks. Five servers were affected and approximately 1.3 terabytes of data were encrypted, disrupting outpatient registration, billing, report generation, appointments and lab services. Because AIIMS treats roughly 38 lakh (3.8 million) patients a year and holds highly sensitive records, including those of VIPs, it became one of the most scrutinised attacks on healthcare infrastructure in India.

  • When did the AIIMS Delhi cyber attack take place?

    The attack was detected on 23 November 2022, when staff found the eHospital server down and infected files renamed with new extensions. Digital services were disrupted for about two weeks, and online patient registration resumed on 6 December 2022. CERT-In’s preliminary findings were placed before Parliament on 16 December 2022, confirming five affected servers and roughly 1.3 TB of encrypted data. A separate, less serious attack hit Delhi’s Safdarjung Hospital around 4 December 2022.

  • Who was behind the AIIMS Delhi cyber attack?

    The attacker or attackers were never officially identified. Delhi Police and government ministers described the incident as a deliberate, targeted conspiracy, and the National Investigation Agency (NIA) opened a probe. Police sources suspected a foreign origin, pointing to locations in China and Hong Kong, while a Times Now report cited possible China or North Korea links. The National Cyber Coordination Centre noted features resembling the LockBit ransomware family. None of this was formally confirmed, and the case was referred to the CBI and Interpol.

  • Was a ransom demanded in the AIIMS cyber attack, and was it paid?

    Reporting on the ransom was inconsistent. Press Trust of India reported that the hackers had allegedly demanded around Rs 200 crore (about $24.5 million) in cryptocurrency, while a later email to Hindustan Times claimed a demand of 30 bitcoins with a 5 December 2022 deadline. However, a police official told Reuters that no ransom demand had been made for restoring the servers. There is no confirmation that AIIMS paid any ransom.

  • How much data was affected in the AIIMS attack?

    According to CERT-In’s analysis presented to Parliament, five AIIMS servers were compromised and approximately 1.3 terabytes of data were encrypted. Some news reports alleged that around 4 crore (40 million) patient profiles, including records of VIPs, may have been exposed and even offered for sale on the dark web, but government sources said claims of patient data theft had ‘no factual basis’. The encryption of about 1.3 TB is the figure that was officially confirmed.

  • What kind of data was involved in the AIIMS breach?

    The affected systems held Personally Identifiable Information (PII) of patients and healthcare workers, alongside administrative records covering blood donors, ambulances, vaccinations, caregivers and employee login credentials. Reports suggested the data could include the medical records of high-profile individuals such as former prime ministers, ministers, bureaucrats and judges. Whether this data was actually exfiltrated, as opposed to encrypted in place, remained disputed throughout the investigation.

  • How did the attackers gain access to AIIMS’s systems?

    No single entry point was officially confirmed. CERT-In stated that the servers were compromised due to improper network segmentation, which allowed the disruption to spread to critical applications. Separately, The Hindu reported that AIIMS ran the Zimbra email software, which had known vulnerabilities dating back to early 2022, and that some staff used non-official email addresses, both flagged as possible weaknesses. AIIMS’s cyber security posture was reportedly assessed as ‘not up to the mark’.

  • How long was AIIMS down, and how did it recover?

    Digital services were disrupted for roughly two weeks. AIIMS, the NIC and CERT-In sanitised the network, scanned thousands of computers and installed antivirus protection before restoring systems in phases. Online patient registration resumed on 6 December 2022, and the laboratory information system and other dependent databases were brought back ahead of full e-hospital restoration. Throughout the outage, emergency and routine care continued in manual mode.

  • What was the impact on hospital operations and patients?

    With the eHospital system down, AIIMS could not process electronic patient registration, billing, report generation, appointment scheduling or smart-lab services, all of which reverted to manual mode. Doctors reported slower workflows, an inability to view previous reports or imaging, and a higher risk of errors. The daily number of patients seen in outpatient departments and diagnostics dropped noticeably, hitting those travelling from outside Delhi especially hard.

  • Were any other hospitals or medical bodies affected?

    Yes. Around 4 December 2022, Delhi’s Safdarjung Hospital reported a separate, less severe attack that took a server down for about a day with no serious data loss. Separately, NDTV reported roughly 6,000 hacking attempts on the Indian Council of Medical Research (ICMR) website on 30 November 2022, with the source IP traced to a blacklisted address in Hong Kong. These incidents heightened concern about the wider exposure of India’s health sector. 

  • How did AIIMS and the Indian government respond?

    AIIMS isolated infected systems, engaged CERT-In and the NIC, and brought in consultancy Ernst & Young, while Delhi Police’s IFSO unit registered a case under Section 385 IPC and the IT Act. Multiple agencies — Delhi Police, CERT-In, the Ministry of Home Affairs and the NIA — joined the investigation, two system analysts were suspended, and the case was escalated to the CBI and Interpol. AIIMS also issued manual-mode standard operating procedures to keep clinical services running during the outage.

  • What can organisations learn from the AIIMS cyber attack?

    The AIIMS incident shows how a single ransomware event can paralyse critical services — in this case patient care — far beyond pure data loss. The key lessons are that proper network segmentation, patched software, offline backups and strong access controls are essential; that healthcare and other essential-service providers are high-value targets; and that tested incident response plans and crisis exercises are vital to rapid recovery. Cyber Management Alliance helps organisations build these capabilities through training, cyber crisis tabletop exercises and incident response planning.

We are industry experienced practitioners when it comes to cyber security training & cyber security consultancy services

1487652208_graduationcap

Training

We offer a host of courses including our NCSC Assured Training in Cyber Incident Planning and Response and our NCSC Assured Training in Building and Optimising Incident Response Playbooks.

1487652701_like

Virtual CISO Services

Hands On, full-support 'Security As a Service', specifically designed for organisations that require access to experienced cybersecurity, governance, risk and compliance professionals.

1487652784_calendar-3

Virtual Cyber Assistant

A unique, affordable, subscription-based, cybersecurity service for small to medium businesses, offering 280+ services in cybersecurity.

1487652846_microphone

Cyber Crisis Tabletop Exercises

Scenario-based, verbally-simulated tabletop attack exercises that test your organisation's ability to effectively respond to a cyber-attack.

1487652632_search

Ransomware Tabletop Exercise

Measure your organisation’s Ransomware Readiness with a unique blend of verbal and visual simulations and ransomware scenario walkthroughs.

1487652567_line-chart

Executive Cyber Awareness Sessions

Specially designed for executive management, CEOs and boards of directors, engaging them in a business context to help explain the threats and risks from cyber-attacks.

How we use your data:

  • The form above collects personal information so we may email you the requested information and pressing the "Get your free copy now"  button acts as informed consent for this processing purpose. Consequently we may be in touch to:

    • Update you when we host our ground-breaking Wisdom of Crowds events in your country or region.
    • Keep you posted on free resources and documents around Wisdom of Crowds events and its outputs. (For example, we tend to create insightful mind maps and we also are the creators of free to view Insights with Cyber Leaders Video Interviews. )
    • Ping you a note about upcoming FREE educational webinars on GDPR and Cybersecurity.
    • Inform you of any upcoming Data Breach Response or Cyber Incident Response training.  
  • Using the information from this page we will NOT sell or market to you any of our consultancy or trusted advisory services.  
  • In its purest interpretation, this act of us communicating with you is direct marketing and is processed on the basis of our legitimate interest and your engaging in our services. All marketing communication will include an unsubscribe button or other method of ending communication.