Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationransomware-group-operationhealthcare-sector-threatmass-credential-exposure

University of Hawaii Cancer Center Ransomware Breach and Delayed Disclosure

Updated 3mo agoFirst seen Jan 13, 20265 sources

The University of Hawaii (UH) Cancer Center disclosed that a ransomware intrusion affecting a single cancer research project led to the encryption of systems and the theft of a limited set of research files, including some legacy documents from the 1990s containing Social Security numbers used to identify study participants. UH reported the incident occurred in late August 2025 and said clinical operations and patient care were not impacted, but recovery and investigation were delayed due to the extent of encryption damage; UH also stated it engaged external experts, isolated affected systems, and negotiated with the attackers, including paying to obtain a decryptor and seeking assurances of deletion of stolen data.

The disclosure drew scrutiny because UH reportedly notified the state legislature well after Hawaii’s 20-day breach reporting deadline, and the university has not provided key details such as the specific research project, the number of affected individuals, or concrete measures proving the stolen data was not exposed after negotiations. Separate reporting on unrelated ransomware activity included Everest claiming a breach of Nissan with an alleged 900GB data theft and Trellix research describing CrazyHunter ransomware targeting Taiwan healthcare organizations; those items do not appear connected to the UH Cancer Center incident beyond being ransomware-related.

Share:
University of Hawaii Cancer Center Ransomware Breach and Delayed Disclosure
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

9 events from the most recent confirmed update back to the earliest known activity.

9 EVENTS
Jan 15, 20265mo ago

Cancer Center implements post-incident security hardening

Following the attack, UH reported remediation measures including endpoint protection deployment, password resets, system replacement, firewall replacement, 24/7 monitoring, and third-party security audits. These steps were described as part of recovery and efforts to prevent recurrence.

UH says affected individuals will be notified once contact details are confirmed

By mid-January 2026, the cancer center said it was preparing notification letters for impacted research participants, including some from 1990s studies. It stated that notices were delayed while current contact information was being determined and that credit monitoring and identity protection would be offered.

Jan 12, 20265mo ago

Official report to Hawaii Legislature details delayed breach disclosure

About four months after the attack, the university submitted an official report to the Hawaii Legislature in January 2026 describing the incident, the stolen data, and response actions. The timing drew concern because it appeared to exceed statutory notification expectations.

Dec 1, 20257mo ago

University discloses incident to Hawaii state officials

In December 2025, the University of Hawaii reported the ransomware incident to state officials. The disclosure included that a ransom had been paid to obtain a decryptor and seek deletion of stolen data.

University pays ransom and obtains decryptor

The university engaged with the threat actors, paid a ransom through third-party experts, and obtained a decryption tool to restore encrypted data. It also received assurances that the stolen data would be deleted or 'securely destroyed.'

Later analysis identifies legacy files with Social Security numbers

Subsequent investigation found older documents from 1990s studies containing Social Security numbers and other participant information among the stolen files. This expanded the breach's sensitivity and the population potentially affected.

Sep 1, 202510mo ago

Initial review finds research data exposure without clear personal identifiers

Early analysis indicated that most compromised files were cancer study research data and initially suggested limited exposure of directly identifying information. The impact was understood to center on one research project.

Aug 31, 202510mo ago

Attackers encrypt research files and steal study data

During the August 2025 incident, threat actors encrypted systems and exfiltrated research files from the UH Cancer Center. Clinical operations and the electronic medical record system were reported as unaffected, but restoration was significantly disrupted.

UH Cancer Center detects ransomware intrusion and isolates affected systems

Around 2025-08-31, the University of Hawaii Cancer Center discovered unauthorized access tied to a ransomware attack affecting a single research project. The center disconnected or isolated affected servers and began an investigation with external cybersecurity assistance.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

15 LINKEDOpen in app
Threat actors
2 linked
Malware
1 linked
Affected products
2 linked
E-Business SuiteOracle E-Business Suite
Organizations
10 linked
University of Hawaii Cancer CenterBleepingComputerHawaiian AirlinesOracleRescanaCovenant HealthBrightspeedHITech HuiSOCDefendersGovInfoSecurity
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.