Within Cyber Enablers

What If Cyberattacks Cripple an Outbreak Response?

Compromised hospitals, surveillance networks and medical logistics could turn a severe outbreak into a far harder crisis to contain.

34 sources 3 graphics
Preview for What If Cyberattacks Cripple an Outbreak Response?

On this page

  • Which health and emergency systems could be targeted
  • How disruption could delay detection and treatment
  • Where redundancy and incident response could limit harm

Introduction

Within debates about AI doom and existential risk, cyberattacks on health systems are not usually presented as a direct route to human extinction. Instead, they are treated as a potential force multiplier. If a severe biological emergency such as a fast-moving pandemic were already under way, simultaneous cyberattacks on hospitals, disease surveillance networks, laboratories or medical supply chains could make an already dangerous situation significantly harder to control. The concern is that increasingly capable AI systems could enable attackers to coordinate broader, faster and more adaptive campaigns against multiple organisations at once, increasing pressure on public-health defences at the moment they are needed most.

Defence Failure illustration 1

This remains a conditional scenario rather than an established prediction. Real-world incidents have demonstrated that cyberattacks can delay healthcare, interrupt diagnostics and force hospitals to operate with degraded systems. Whether these disruptions could materially worsen a civilisation-scale biological crisis depends on many additional factors, including the severity of the outbreak, the resilience of health systems, international coordination and the effectiveness of emergency response plans. The uncertainty is substantial, but the combination of biological and cyber crises has become an increasingly serious area of preparedness planning.[World Health Organization]who.intWorld Health OrganizationWHO Director-General's remarks at Meeting of the UN Security Council on threats posed by ransomware attacks agai…

Which health and emergency systems could be targeted?

A major outbreak depends on many digital systems working together. During routine conditions, temporary disruption may be manageable. During a rapidly expanding epidemic, however, delays can cascade across the response.

Systems frequently discussed in preparedness planning include:

  • Disease surveillance networks, which collect reports from hospitals and laboratories to detect emerging outbreaks and monitor their spread.
  • Hospital clinical systems, including electronic patient records, imaging systems and intensive care monitoring.
  • Diagnostic laboratories, which process tests needed to confirm infections, monitor variants and guide treatment decisions.
  • Public-health communication systems, which distribute alerts, guidance and situational reports between agencies.
  • Medical logistics networks, responsible for coordinating medicines, vaccines, protective equipment and laboratory supplies.
  • Emergency coordination platforms, used by governments and health authorities to allocate scarce resources and monitor capacity.

The World Health Organization (WHO) describes surveillance as the continuous collection and analysis of health data that provides early warning of outbreaks and guides intervention. If those data become unavailable or delayed, authorities may lose valuable time when attempting to identify hotspots or evaluate whether control measures are working.[World Health Organization]who.intWorld Health Organization Surveillance in emergenciesWorld Health OrganizationSurveillance in emergenciesJune 24, 2022…Published: June 24, 2022

How disruption could delay detection and treatment

The greatest concern is usually not immediate physical destruction but the loss of timely information.

During an outbreak, health authorities rely on rapid reporting from many independent organisations. If hospitals cannot upload case data, laboratories cannot report results promptly or surveillance databases become unavailable, decision-makers may receive an incomplete picture of where infections are spreading.

That can affect several stages of outbreak management:

  • slower recognition of emerging clusters;
  • delayed confirmation of diagnoses;
  • reduced visibility into hospital capacity;
  • slower contact tracing where it remains useful;
  • less efficient allocation of medicines, vaccines and specialist staff;
  • poorer forecasting of where resources will soon be needed.

Hospitals may also revert to paper-based processes. Although this allows essential care to continue, it generally reduces efficiency, increases administrative workload and makes coordination across multiple institutions more difficult. During a widespread emergency, even relatively small delays repeated across hundreds of facilities can accumulate into significant operational problems.[World Health Organization]who.intWorld Health Organization Surveillance in emergenciesWorld Health OrganizationSurveillance in emergenciesJune 24, 2022…Published: June 24, 2022

Defence Failure illustration 2

What recent incidents show about healthcare disruption

Several well-documented cyber incidents illustrate the kinds of disruption that could matter during a biological emergency, even though they did not occur alongside an existential-scale outbreak.

In March 2020, a ransomware attack forced Brno University Hospital in the Czech Republic to shut down much of its network, postpone procedures and transfer patients just as the country entered a COVID-19 state of emergency. The timing highlighted how cyber disruption can coincide with rapidly escalating public-health demands.[World Health Organization]who.intWorld Health OrganizationWHO Director-General's remarks at Meeting of the UN Security Council on threats posed by ransomware attacks agai…

The 2021 ransomware attack on Ireland’s Health Service Executive affected approximately 80% of its IT environment, disrupting diagnostic imaging, radiotherapy scheduling and outpatient services while staff reverted to manual processes. Recovery took many months, illustrating how cyber incidents can produce prolonged operational consequences rather than brief interruptions.[World Health Organization]who.intWorld Health OrganizationWHO Director-General's remarks at Meeting of the UN Security Council on threats posed by ransomware attacks agai…

The UK’s National Health Service experienced major disruption during the 2017 WannaCry ransomware outbreak. Ambulances were diverted, thousands of appointments were cancelled and many organisations lost access to essential digital services. Investigations found that available software patches had not been universally deployed before the attack, demonstrating that preparedness and maintenance can substantially influence outcomes.[nao.org.uk]nao.org.ukInvestigation: Wanna Cry cyber attack and the NHSInvestigation: WannaCry cyber attack and the NHS - NAO press release…

More recently, the 2024 ransomware attack affecting Synnovis, a pathology services provider supporting several London hospitals, disrupted blood testing, delayed operations and required extensive contingency arrangements despite hospitals continuing emergency care. The incident showed how attacks on third-party providers can ripple across multiple healthcare organisations simultaneously.[ft.com]ft.comLondon hospitals declare critical incident after cyber attackLondon hospitals declare critical incident after cyber attack

These incidents occurred without a civilisation-threatening pandemic. They therefore cannot demonstrate existential consequences, but they provide concrete evidence that healthcare cyberattacks can reduce capacity precisely when medical systems are under exceptional pressure.

Why AI could increase concern without changing the basic mechanism

The underlying mechanism does not depend on AI. Hospitals have experienced disruptive cyberattacks for years.

The concern within AI-risk discussions is that more capable AI systems could increase the scale, speed or coordination of such campaigns. Rather than enabling entirely new forms of attack, advanced AI might reduce the expertise and manpower needed to identify vulnerable organisations, adapt malicious software, automate reconnaissance or manage simultaneous operations against many targets.

If attackers could launch broader campaigns during an unfolding biological emergency, defensive organisations might face multiple failures at once instead of isolated incidents. This could stretch already limited cybersecurity teams while clinical staff were simultaneously dealing with surging patient numbers.

Current evidence does not show that AI systems autonomously conduct sophisticated campaigns at this scale. The possibility is treated as a future capability question rather than an established present-day reality, and many researchers expect AI to strengthen cyber defence as well as offence.[arXiv]arxiv.orgOpen source on arxiv.org.

Where redundancy and incident response could limit harm

Preparedness planning assumes that cyber incidents will occur and therefore emphasises resilience rather than perfect prevention.

Important defensive measures include:

  • maintaining secure offline backups of essential systems;
  • rehearsing manual clinical workflows before emergencies occur;
  • segmenting hospital networks so infections cannot easily spread;
  • rapidly applying security updates to critical systems;
  • sharing threat intelligence between healthcare organisations;
  • maintaining alternative communication channels if primary networks fail;
  • regularly exercising joint cyber and public-health emergency response plans.

WHO and partner organisations increasingly frame cyber resilience as part of health security rather than merely an information technology problem. Their guidance emphasises staff training, incident response planning, coordination with national cybersecurity agencies and routine exercises designed to preserve patient care even when digital systems fail.[World Health Organization]who.intWorld Health Organization Cyber-attacks on critical health infrastructureWorld Health Organization Cyber-attacks on critical health infrastructure

Research has also explored collaborative approaches in which hospitals share anonymised indicators of ransomware activity, allowing defensive systems to recognise emerging attacks more quickly while preserving patient privacy. Although still an active research area, such work reflects the broader emphasis on resilience across entire healthcare networks rather than isolated organisations.[arXiv]arxiv.orgOpen source on arxiv.org.

Defence Failure illustration 3

How this fits into AI doom arguments

This scenario occupies a specific place within broader AI doom discussions. The argument is not that cyberattacks on hospitals alone would plausibly cause human extinction. Rather, they could weaken society’s ability to respond if another catastrophic threat—especially a severe biological emergency—were already unfolding.

Whether that combination could contribute to existential risk depends on many uncertain assumptions: the severity of the pathogen, the geographic scale of the cyber disruption, the resilience of international health systems, the availability of manual workarounds and the effectiveness of emergency coordination under pressure.

For that reason, most serious analyses treat healthcare cyber resilience as one layer of defence within wider efforts to reduce catastrophic biological and AI-related risks. Strengthening surveillance, improving incident response and building redundant health infrastructure may reduce vulnerabilities regardless of whether future cyber capabilities are significantly enhanced by advanced AI.

Amazon book picks

Further Reading

Books and field guides related to What If Cyberattacks Cripple an Outbreak Response?. Use these as the next step if you want deeper reading beyond the article.

eBay marketplace picks

Marketplace Samples

Live-tested eBay searches with available results related to this page.

UsingUSA

Selected fromcybersecurity poster oneBay.co.uk.

Endnotes

1. Source: who.int
Link:https://www.who.int/news-room/speeches/item/who-director-general-s-remarks-at-meeting-of-the-un-security-council-on-threats-posed-by-ransomware-attacks

Source snippet

World Health OrganizationWHO Director-General's remarks at Meeting of the UN Security Council on threats posed by ransomware attacks agai...

2. Source: who.int
Title: World Health Organization Cyber-attacks on critical health infrastructure
Link:https://www.who.int/news-room/questions-and-answers/item/cyber-attacks-on-critical-health-infrastructure

3. Source: arxiv.org
Link:https://arxiv.org/abs/2407.17347

4. Source: who.int
Title: World Health Organization Surveillance in emergencies
Link:https://www.who.int/emergencies/surveillance

Source snippet

World Health OrganizationSurveillance in emergenciesJune 24, 2022...

Published: June 24, 2022

5. Source: who.int
Link:https://www.who.int/news/item/06-02-2024-who-reports-outline-responses-to-cyber-attacks-on-health-care-and-the-rise-of-disinformation-in-public-health-emergencies

Source snippet

World Health OrganizationWHO reports outline responses to cyber-attacks on health care and the rise of disinformation in public health em...

6. Source: nao.org.uk
Title: Investigation: Wanna Cry cyber attack and the NHS
Link:https://www.nao.org.uk/press-releases/investigation-wannacry-cyber-attack-and-the-nhs/

Source snippet

Investigation: WannaCry cyber attack and the NHS - NAO press release...

7. Source: ft.com
Title: London hospitals declare critical incident after cyber attack
Link:https://www.ft.com/content/64ac2bd3-7bff-4323-9263-c70fa0b6ca51

8. Source: arxiv.org
Link:https://arxiv.org/abs/2106.05434

9. Source: who.int
Title: International health regulations
Link:https://www.who.int/health-topics/international-health-regulations/

11. Source: extranet.who.int
Link:https://extranet.who.int/ssa/LeftMenu/PublicReportList.aspx

12. Source: cdc.gov
Link:https://www.cdc.gov/orr/about/

13. Source: england.nhs.uk
Link:https://www.england.nhs.uk/long-read/case-study-wannacry-attack/

Additional References

14. Source: wired.com
Link:https://www.wired.com/story/nhs-wannacry-response-ransomwar

Source snippet

In response, the UK government outlined a plan to enhance NHS cybersecurity, allocating an additional £21 million, on top of the previous...

15. Source: thetimes.co.uk
Link:https://www.thetimes.co.uk/article/cyber-attack-nhs-hospitals-major-incident-uk-cd8z6jprc

Source snippet

King's College Hospital, Guy's and St Thomas' trusts, and their associated hospitals, including Royal Brompton and Evelina London Childre...

16. Source: youtube.com
Link:https://www.youtube.com/watch?v=MvfgapCDylc

Source snippet

This video selection details real-world incidents, preparedness frameworks, and operational vulnerabilities where targeted cyberattacks d...

17. Source: youtube.com
Link:https://www.youtube.com/watch?v=SyGFPLdW2kc

Source snippet

Paris hospital falls victim to $10m cyberattack: 'Hospitals are very attractive for attackers'...

18. Source: youtube.com
Link:https://www.youtube.com/watch?v=anGlvoOj768

Source snippet

Cybersecurity for the Clinician - Episode 1: Cyber Safety Is Patient Safety...

19. Source: youtube.com
Title: Major cyber attack on UK hospitals causes operations to be cancelled
Link:https://www.youtube.com/watch?v=nmhscZ3Icyc

Source snippet

Live from AHA Annual Meeting: Leading edge CEO discusses planning for Health care Cyberattacks...

20. Source: youtube.com
Title: Cybersecurity for the Clinician
Link:https://www.youtube.com/watch?v=rS0gT6bIiYw

Source snippet

Major cyber attack on UK hospitals causes operations to be cancelled...

21. Source: cdc.gov
Title: Biological and Chemical Terrorism:Strategic Plan for Preparedness and Response
Link:https://www.cdc.gov/mmwr/preview/mmwrhtml/rr4904a1.htm

22. Source: pubmed.ncbi.nlm.nih.gov
Link:https://pubmed.ncbi.nlm.nih.gov/36580326/

23. Source: pubmed.ncbi.nlm.nih.gov
Link:https://pubmed.ncbi.nlm.nih.gov/36945857/