Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
ransomware-group-operationbreach-disclosure-notificationmass-credential-exposureoperational-disruption

Ransomware and data-breach disclosures across education, critical infrastructure, and healthcare

Updated 3mo agoFirst seen Feb 5, 20265 sources

Rome’s La Sapienza University shut down network systems as a precaution after a cyberattack caused widespread disruption and left its website offline; Italian media attributed the incident to a suspected ransomware operation linked to pro-Russian actor Femwar02, with reported tradecraft resembling Bablock/Rorschach-style fast encryption. Separately, Romania’s national oil pipeline operator Conpet reported a cyberattack that disrupted corporate IT and took down www.conpet.ro while leaving OT/SCADA and pipeline transport operations unaffected; Qilin claimed responsibility, alleging theft of nearly 1TB of data and posting sample documents (including financial data and passport scans) to support extortion claims.

In the U.S., government services contractor Conduent faced expanding breach impact from its January 2025 ransomware incident, with notifications indicating exposure potentially reaching dozens of millions; reported affected data includes names, Social Security numbers, and medical/health insurance information, with at least 15.4M impacted in Texas and 10.5M in Oregon per state disclosures. Additional healthcare-sector disclosures included a ransomware-linked intrusion at Insightin Health (unauthorized access in September 2025; Medusa claimed exfiltration of 378GB) and a separate compromise at Clinic Service Corporation (August 2025 access window), while Central Ozarks Medical Center reported a criminal cyberattack affecting 11,818 individuals with exposure of PHI/PII (including SSNs and financial/insurance data). Other items in the set were not incident-specific: an HHS-OIG audit describing web application security weaknesses at a large hospital, and general guidance/education pieces on the value of medical records to attackers and CISA insider-threat guidance.

Share:
Ransomware and data-breach disclosures across education, critical infrastructure, and healthcare
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

14 events from the most recent confirmed update back to the earliest known activity.

14 EVENTS
Feb 5, 20265mo ago

Conduent breach totals expand to tens of millions

Updated breach figures reported in early February 2026 showed the Conduent incident affected millions more Americans than previously known, including at least 15.4 million in Texas and 10.5 million in Oregon. Notifications were ongoing, with completion planned by early 2026.

Reports attribute Sapienza attack to Femwar02 ransomware

Italian media reported the Sapienza incident was a ransomware attack attributed to pro-Russian actor Femwar02, with malware resembling Bablock or Rorschach and causing data encryption. The report said a ransom note was present but not opened to avoid triggering a 72-hour timer.

Sapienza University shuts down systems after cyberattack

Sapienza University in Rome disclosed a cyberattack that disrupted IT services and led to an immediate shutdown of network systems to protect data integrity. Authorities were notified, a technical task force was formed, and recovery began while digital services remained unavailable.

Qilin claims Conpet breach and posts proof samples

The Qilin ransomware group listed Conpet on its leak site, alleging it stole nearly 1 TB of data. It published sample images of internal documents, including financial records and passport scans, as proof of compromise.

Conpet discloses cyberattack affecting corporate IT and website

Romanian oil pipeline operator Conpet announced a cyberattack disrupted its corporate IT systems and took its public website offline, while saying pipeline transport operations and OT systems were unaffected. The company began restoration with national cybersecurity authorities and filed a criminal complaint with DIICOT.

Safeway gang claims Conduent attack and data theft

The Safeway ransomware gang claimed responsibility for the Conduent incident and alleged it stole more than 8 TB of data. Later breach notifications linked the attack to at least 15.4 million affected people in Texas and 10.5 million in Oregon, with more notifications sent in other states.

Feb 4, 20265mo ago

COMC discloses breach affecting nearly 12,000 patients

Central Ozarks Medical Center disclosed that a criminal cyberattack potentially exposed the personal and protected health information of 11,818 individuals. The organization offered at least 12 months of credit monitoring and identity theft protection and said it was implementing cybersecurity enhancements.

Nov 19, 20257mo ago

Middlesex Sheriff’s Office completes breach file review

After a January 2025 breach and multi-agency investigation, the Middlesex Sheriff’s Office completed its file review on 2025-11-19. The incident was reported to HHS OCR as affecting 501 individuals as a placeholder.

Nov 10, 20257mo ago

Central Ozarks Medical Center identifies possible data compromise

Central Ozarks Medical Center determined around 2025-11-10 that data may have been accessed or acquired without authorization in a criminal cyberattack affecting patient information.

Sep 17, 20259mo ago

Insightin Health attackers access network over six days

Forensics found unauthorized access to Insightin Health's network occurred between 2025-09-17 and 2025-09-23, exposing protected health information such as names, dates of birth, Medicare Beneficiary Identifiers, and insurance or provider-related data.

Sep 1, 202510mo ago

Insightin Health detects suspicious activity

Insightin Health detected suspicious activity in September 2025 and later disclosed a cyber incident involving unauthorized network access. Medusa was reported to have claimed responsibility and alleged theft of 378 GB of data.

Aug 17, 202510mo ago

Clinic Service Corporation detects hacking incident

Clinic Service Corporation detected the incident on 2025-08-17 and later notified regulators and offered affected individuals credit monitoring and identity theft protection.

Aug 10, 202511mo ago

Clinic Service Corporation network accessed in August 2025 breach

Clinic Service Corporation said unauthorized access to its systems occurred between 2025-08-10 and 2025-08-17, 2025, exposing extensive PII and PHI including diagnoses, treatment details, and insurance and claims data.

Jan 1, 20251y ago

Conduent ransomware attack disrupts operations

A ransomware attack on Conduent in January 2025 caused multi-day operational outages. The company later said stolen datasets contained significant end-user personal information tied to client services.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

24 LINKEDOpen in app
Organizations
14 linked
Check Point Software TechnologiesSapienza University of RomeLee EnterprisesAsahi Group HoldingsSynnovisTinesCovenant HealthNissan Motor Co., Ltd.AdventHealth Daytona BeachCentral Ozarks Medical CenterElectrica GroupInsightin HealthConpetClinic Service Corporation
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.