Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
breach-disclosure-notificationransomware-group-operationmass-credential-exposurehealthcare-sector-threat

Ransomware and data-extortion incidents drive new breach disclosures across healthcare, aviation, and hospitality

Updated 3mo agoFirst seen Feb 25, 20264 sources

Multiple organizations disclosed or were linked to ransomware/data-extortion activity with material operational or privacy impact. Air Côte d’Ivoire confirmed a cyberattack affecting parts of its information systems after INC ransomware claimed theft of 208 GB and threatened to leak data, while the airline said it engaged the national CERT and external experts to contain impact and maintain flight operations. In the US healthcare sector, University of Mississippi Medical Center (UMMC) reported a ransomware incident that forced statewide clinic closures and disrupted access to Epic electronic medical records, prompting engagement with the FBI and CISA and use of downtime procedures to sustain patient care. Separately, Conduent’s earlier ransomware-linked breach continued to expand in scope, with breach notifications indicating at least ~25 million people affected across multiple states and exposure of sensitive PII (including SSNs and health/insurance data). Wynn Resorts also confirmed an unauthorized party accessed and stole employee data after being listed by the ShinyHunters extortion group, with the company stating the actor claimed the data was deleted and that guest operations were not impacted.

Other items in the set describe distinct, unrelated security events and broader threat research rather than the same incident: alleged data leaks involving Burger King France and Wendy’s UK; Qilin ransomware claims against a New York City transit union; Russian cyber operations against Ukraine’s power grid focused on intelligence collection; and a New Zealand healthcare application (MediMap) taken offline after apparent unauthorized access and patient record tampering (e.g., records marked deceased). Additional references cover threat research and trends (airline brand impersonation domains, edge-device exploitation telemetry, MuddyWater’s Operation Olalampo, Google Ads cloaking via 1Campaign, freight/logistics phishing by “Diesel Vortex,” and various governance/AI/5G/quantum commentary), which provide context on the threat environment but do not substantively report on the same specific breach event.

Share:
Ransomware and data-extortion incidents drive new breach disclosures across healthcare, aviation, and hospitality
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

10 events from the most recent confirmed update back to the earliest known activity.

10 EVENTS
Feb 25, 20264mo ago

Air Côte d’Ivoire publicly discloses cyberattack

Air Côte d’Ivoire publicly confirmed the cyberattack and said it was working with national incident responders and technical specialists. The airline emphasized that flight safety and operational continuity were being maintained.

Feb 24, 20264mo ago

Conduent breach tally grows to at least 25 million people

State breach notifications and reporting indicated that the Conduent incident affected at least 25 million people, with the largest impacts reported in Oregon and Texas. Exposed data included Social Security numbers and medical or health insurance information.

Wynn Resorts confirms employee data theft after extortion threat

Wynn Resorts confirmed that an unauthorized party stole certain employee data and said it had launched an investigation with outside cybersecurity experts. The company said guest operations and physical properties were not affected and that the attackers claimed the stolen data had been deleted.

INC ransomware claims Air Côte d’Ivoire theft and sets leak deadline

The INC ransomware operation claimed it stole 208 GB of data from Air Côte d’Ivoire and threatened to publish it by February 24, 2026. This public claim preceded the airline’s disclosure of the incident.

Feb 23, 20264mo ago

Wynn Resorts appears on ShinyHunters leak site with extortion deadline

ShinyHunters posted Wynn Resorts on its leak site, claiming to have stolen more than 800,000 employee records containing personal information and demanding contact by February 23, 2026. The post was later removed, suggesting possible negotiations or a disputed claim.

UMMC closes statewide clinics and activates emergency response

Following the attack, UMMC shut down all statewide clinic locations, canceled outpatient surgeries, procedures, and imaging appointments, and activated its Emergency Operations Plan. Hospital services continued under downtime procedures while the network was proactively taken offline for assessment.

UMMC ransomware attack disrupts IT and medical records access

A ransomware attack hit the University of Mississippi Medical Center, disrupting multiple IT systems including Epic electronic medical records. The incident prevented normal access to records and affected clinical operations across the organization.

Feb 1, 20265mo ago

Air Côte d’Ivoire systems are compromised in cyberattack

Air Côte d’Ivoire said parts of its information systems were compromised in a cyberattack earlier in February 2026. The airline engaged Côte d’Ivoire’s CERT and technical experts while maintaining that flight operations remained stable.

Oct 1, 20259mo ago

Conduent publishes hard-to-find incident notice page

In October 2025, Conduent published an incident notice page about the breach, but the page reportedly did not explicitly mention a cybersecurity incident and included a noindex tag that made it harder to discover via search engines.

Jan 1, 20251y ago

Conduent suffers ransomware attack tied to later data breach

Conduent was hit by a cyberattack in January 2025 that was later claimed by a ransomware group. The incident ultimately led to the exposure of sensitive personal data processed for U.S. state benefit and related services.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

35 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Affected products
4 linked
SignalZendeskDropboxDropbox
Organizations
29 linked
Envoy AirRecorded FutureQantasIberia Líneas Aéreas de EspañaAir Côte d'IvoireSalesforceBettermentChange HealthcareZendeskEpic Systems CorporationAtlassianBleepingComputerTechCrunchSAPOktaDropboxConduentMicrosoft CorporationAdobeOracleSlack TechnologiesPornhubSoundcloudGoogleMatch GroupPanera BreadCanada GooseUniversity of Mississippi Medical CenterWynn Resorts
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.