Salus Trieste ransomware attack: systems down since 31 August
The Salus Trieste ransomware attack has left the Italian clinic’s systems unusable since 31 August, severely disrupting normal operations. This incident highlights the growing threat of ransomware attacks targeting healthcare providers, which often hold sensitive patient data and rely heavily on digital infrastructure for daily care.
What happened: Timeline and attack specifics
On 31 August 2023, Salus di Trieste, a well-known private clinic in the Friuli Venezia Giulia region, experienced a sudden and comprehensive IT shutdown. The cause was quickly identified as a ransomware attack, which encrypted critical systems and rendered them inaccessible to staff. Medical records, appointment systems and other vital resources were affected, forcing the clinic to adopt manual procedures and limiting some patient services.
Attackers and tactics
The ransomware attack has been attributed to a Russian-Albanian cybercrime group, previously linked to other high-profile incidents, including the theft at the Lipizza casino. This group is known for sophisticated intrusion tactics and has a history of targeting organisations with valuable data.
In this case, the attackers deployed ransomware that locked clinic staff out of their IT environment. A ransom demand soon followed, with the criminals threatening to keep systems locked unless payment was made. The exact amount demanded has not been disclosed.
Immediate response and investigation
- 31 August: Systems at Salus Trieste become unusable due to ransomware.
- Immediately after: The clinic engages a specialist cybersecurity firm to handle incident response and digital forensics.
- Concurrent: The Italian State Police (Polizia di Stato) are called in to investigate the attack and support recovery efforts.
- Ongoing: The clinic assesses whether any patient data, including sensitive health records, have been exfiltrated by the attackers. As of now, there is no confirmation of data leakage.
Impact on Salus Trieste and its patients
The Salus Trieste ransomware attack has had a significant operational impact. With core digital systems encrypted, the clinic has been forced to revert to manual processes. This has affected appointment scheduling, access to patient histories and the delivery of some routine services. For a busy healthcare facility, such disruptions can lead to delays in care and administrative challenges for both patients and staff.
Data at risk: Health records and privacy concerns
One of the most pressing concerns in this attack is the potential exposure of sensitive health data. While Salus Trieste maintains a data backup system, investigators have not yet confirmed if patient records have been exfiltrated. Ransomware attacks on healthcare providers often include a data theft component, with attackers threatening to leak private information if their demands are not met.
The uncertainty about whether data has been copied or stolen means patients and regulators must wait for the results of the ongoing investigation. The clinic has stated it is working closely with authorities and cybersecurity specialists to determine the full scope of the breach.
Ransomware trends in European healthcare
This attack on Salus Trieste is part of a broader trend of ransomware campaigns targeting healthcare institutions across Europe. Such organisations are attractive targets due to the critical nature of their services and the high value of medical data. Attackers often believe that healthcare facilities will be more likely to pay a ransom quickly to restore operations and protect patient privacy.
Key details of the Salus Trieste attack
- Date of incident: 31 August 2023
- Victim: Salus di Trieste (polifvg.it)
- Attack type: Ransomware, attributed to a Russian-Albanian group
- Impact: Systems encrypted and unusable, manual operations in place
- Data exfiltration: Not yet confirmed
- Response: Cybersecurity firm and Italian State Police involved
Why this attack matters
The Salus Trieste ransomware attack underscores the vulnerability of healthcare organisations to cyber threats and the operational risks posed by digital disruptions. Fast, coordinated response is essential to limit damage and investigate possible data breaches. With patient health records possibly at risk, such incidents highlight the need for robust incident response planning and secure backup strategies.
What organisations should do now
Healthcare providers and other critical infrastructure operators should monitor developments in the Salus Trieste case and review their own incident response and data backup processes. Timely, well-tested recovery procedures and collaboration with law enforcement are crucial when facing ransomware threats.
Originally reported by triesteprima.it.





