Security researchers at Fraunhofer SIT have conducted a detailed hospital crisis simulation that exposes both the speed at which ransomware attacks can cripple healthcare infrastructure and the organizational failures that make recovery far harder than most teams expect.
Professor Sebastian Schinzel, who has spent over 20 years in IT security, described the threat landscape as unlike anything he has seen before. He warned of an emerging class of malware that could leverage local LLMs — small language models running on a hospital's own GPUs — to adapt in real time. Then the classic countermeasure of cutting the internet connection may no longer work, because attackers could operate entirely within a compromised network.
The simulation, presented at a conference of German hospital IT leaders in Berlin, used a realistic scenario: the attack begins with open-source intelligence gathering, proceeds to a targeted phishing email, and escalates once an IT administrator's VPN credentials are compromised. From that point, the attacker gains access to the Active Directory, and effectively the entire hospital network.
The simulation assigned 23 participants across 12 roles in a typical German hospital. Decision-making worked reasonably well — the team quickly agreed not to pay ransom and to disconnect from the internet. But information flow broke down. The crisis staff became a one-way street. Documentation proved surprisingly fragile; when someone asked about a measure already decided, no one had recorded it.
Teams consistently underestimated recovery time. While participants estimated a return to normal operations within days, real-world cases show weeks to months are typical. One Frankfurt-area hospital required nearly a full year to recover from an Active Directory compromise — and the data had not even been encrypted.
Schinzel's warning about LLM-enhanced malware represents a frontier concern. If attackers can run a small model on captured GPU hardware within a hospital network, they could potentially generate variant payloads, evade signature-based detection, and adapt their approach based on the hospital's specific defenses — all without external internet connectivity.



