AIIMS Delhi and SolarWinds: When Trust in Digital Infrastructure Collapses

One was a 2 week ransomware siege that forced India’s top public hospital onto pen and paper. The other was a month-long espionage operation, hidden inside trusted software that went undetected across the US government and Fortune 500 companies until a security firm found it by accident. Most major breaches aren’t masterminds at work, they are ordinary, known risks such as an unpatched server, an unwatched build pipeline that became a crisis. AIIMS Delhi and SolarWinds show two different failures: one loud and aimed at a hospital, the other silent and aimed at the software supply chain everyone quietly depends on.

AIIMS Delhi (India, November 2022)

On 23rd November 2022, engineers managing servers at AIIMS New Delhi, a 2,500 bed public hospital, found 5 of roughly 100 servers compromised. The e-Hospital system running registration, admissions, billing and lab scheduling went dark. For nearly two weeks the hospital ran entirely on paper and the digital services weren’t fully restored until 6 December.

Media reports, citing police sources, put the ransom demand at roughly ₹200 crore ($23–24 million), allegedly from LockBit, though no payment or attribution was ever confirmed. What is confirmed is that an estimated 30–40 million patient records were compromised. Delhi Police classified the case as cyberterrorism under Section 66F of the IT Act, and the CBI, NIA, Intelligence Bureau, and CERT-In all joined the probe, with jurisdiction itself a point of confusion.

The root cause was that the AIIMS systems hadn’t been meaningfully upgraded in decades along with the weak network segmentation due to which the 5 compromised servers took down the whole digital backbone. When AIIMS faced a second intrusion attempt in November 2023, the government confirmed no breach and no disruption thus proving that these attacks are survivable when checks are in place.

The SolarWinds Hack (United States, 2019–2020)

SolarWinds’ Orion platform is unglamorous network monitoring software used by roughly 33,000 organizations reflecting that it had privileged access deep inside their networks. Around September 2019, suspected hackers quietly entered SolarWinds’ own build environment. In February 2020, they inserted a backdoor SUNBURST into Orion’s source code before it was compiled and signed. Between March and June 2020, roughly 18,000 customers downloaded that legitimate, malware-laced update. It sat undetected until December 2020, when cybersecurity firm FireEye discovered its own breach traced back to a corrupted Orion update. Attackers had used the access to reach a smaller set of roughly 100–200 high value targets, reportedly including the US Treasury, State, Homeland Security, Commerce, Justice and the Energy departments plus the National Institutes of Health, Microsoft, Cisco, Intel and Deloitte.

Nothing was encrypted or ransomed, this was intelligence gathering, which makes the cost harder to tally but no less real. SolarWinds spent over $40 million in three months on remediation, paid $26 million to settle a shareholder lawsuit, and fought a 2 year SEC case naming its CISO for allegedly misleading investors. Some estimates put economy-wide cleanup costs as high as $100 billion. The deeper lesson, hackers didn’t breach 18,000 organizations one by one, they breached 1 trusted vendor and let its own signed update do the work, since standard practice wasn’t built to question a signed update from a known vendor.

What Each Stakeholder Should Take Away

CEOs and Board Members: AIIMS shows what happens when internal risk goes unexamined for years. SolarWinds shows a signed, trusted update can be the attack itself. Ask which vendors or systems could halt operations for two weeks, treat routine updates as verifiable and rehearse a prolonged outage before one happens for real.

Regulators: India had no data protection law when AIIMS was breached. The DPDP Act wasn’t notified until August 2023, with full enforcement not expected until 2027. The US moved faster, the executive order arrived within 6 months, mandating Zero Trust and SBOM requirements but the adoption has been uneven, and the SEC’s CISO case was ultimately dismissed. Even fast regulation can end up short on teeth.

The Public: AIIMS was directly disruptive — delayed labs, exposed diagnoses. SolarWinds was quieter, aimed at governments and corporations, not consumer data but it’s a reminder that software behind the institutions holding your health data can be compromised even when nothing looks wrong but is worth expecting real security discipline and not just a reassurance message.

Interested:

Check out our website: https://sakram-arch.github.io/Sakram-Public/

Leave a Reply