On October 2, 2026, the Alabama Board of Nursing (ABN) said for the first time that the cybersecurity event that has disrupted its licensing systems since September 1 was a ransomware attack, and that investigators confirmed some data was "collected and downloaded" before the attack was contained. The board's press release says the exposed environment may have held licensee names, dates of birth, Social Security numbers, driver's license numbers, professional licensing information and medical information. ABN says the incident is contained. It is working with the Alabama Office of Information Technology (OIT) and a third-party incident response team, and is cooperating with the FBI and the Alabama Law Enforcement Agency. The board has not named a threat actor, said how many people are affected, or said how the attackers got in. Several outlets report that more than 80,000 nurses are in the current renewal cycle. That figure is a measure of operational impact, not a count of exposed records.
What Happened
The board's own press release (S1, published on abn.alabama.gov) and local and trade press give this timeline:
- August 2026: Forensic investigators later found suspicious activity in ABN's technology environment dating to August, according to the board's October 2 statement.
- September 1, 2026: Malicious activity was confirmed in "portions of the Board's technology environment." ABN posted a service disruption notice that described "a disruption to certain technology systems related to a cybersecurity event." It said systems had been taken offline on purpose (Nurse.org, citing WBRC FOX6).
- September 4: ABN posted its first recovery update (al.com, South Alabama News).
- September 16–19: The online licensing system was still down. Staff were processing applications on paper by hand, and WBRC reported that every paper application received by September 16 had been processed (DysruptionHub). As of Nurse.org's September 19 report, officials said they could not yet determine the nature or scope of the event and had given no restoration date.
- September 21–22: Board staff collected paper applications and payments at six community college campuses: Calhoun, Jefferson State (Shelby-Hoover), Coastal Alabama (Bay Minette), Gadsden State, Shelton State (Martin) and Wallace (Dothan) (al.com, South Alabama News, DysruptionHub).
- October 2: ABN issued the press release confirming ransomware, data exfiltration and possible exposure of sensitive personal information (SPII) and protected health information (PHI). WBMA/ABC 33/40 reported the same day.
The story changed over the month. Throughout September, ABN called this a "cybersecurity event" and gave no detail on cause or data impact. The October 2 statement is the first time it said ransomware was involved or that data had been taken. Readers should treat earlier reports that nothing was known about data loss as out of date, not as conflicting accounts.
Licensing was hit hard. Employers were told to verify licenses through Nursys, but DysruptionHub reports that Nursys data was current only through August 31. Some newly passed NCLEX candidates could not get an Alabama license number. Monitoring applications for nurses on probation were also affected. The board says services are being restored in phases as each system is reviewed and validated.
A separate incident should not be confused with this one. On September 3 the Montgomery Advertiser reported that the Alabama Appellate Courts were investigating possible exposure through a breach of West Publishing's C-Track case management platform. That incident happened in the vendor's environment, with files taken in March 2026. None of the sources connect it to the ABN attack. It is listed here only because both involve Alabama state bodies in the same period.
What Was Taken
ABN confirms that data was exfiltrated, but it does not know exactly what was taken. Its statement says "forensic limitations from the ransomware deployment" mean investigators could not establish "definitively if information belonging to every Alabama nurse, applicant, licensee, or member of the public was fully accessed."
According to the board, the affected data environment "could have included":
- Licensee names
- Dates of birth
- Social Security numbers
- Driver's license numbers
- Professional licensing information
- Medical information (PHI)
Volume: No source gives a number of affected individuals. The figure of more than 80,000 (Nurse.org, DysruptionHub, both citing WBRC) is the number of registered nurses due to renew before the December 31 deadline. It is not a breach count. The real exposed population could be larger, because ABN's statement also covers applicants, licensees in other categories, and "members of the public."
No leak site posting or ransom demand has been reported in any of the sources.
Why It Matters
- Licensing boards hold identity data from start to finish. A nursing board keeps SSNs, government ID numbers, and disciplinary and medical records for a whole state's workforce. That combination is very useful for identity fraud and for targeted phishing aimed at healthcare workers.
- Exfiltration happened before encryption. Investigators confirmed data was downloaded before the ransomware was contained. This is the usual double-extortion pattern. Containing the attack stopped further damage, but it did not stop the data loss.
- Gaps in forensic evidence leave the breach scope open. ABN cannot say for certain who was affected, which suggests logs or artifacts were destroyed or never collected. That makes notification harder and leaves people unsure whether they were exposed.
- The impact on the workforce lasts. A month without online licensing, during a renewal cycle for more than 80,000 nurses and while new graduates wait for credentials, puts pressure on hospital staffing far beyond the board itself.
- There was a long gap before detection. Suspicious activity in August and confirmed malicious activity on September 1 point to the attackers being inside the network before the ransomware ran. Small state agencies with limited security operations capacity are especially exposed to this.
The Attack Technique
The initial access vector has not been disclosed. The facts the sources support are:
- Ransomware was deployed in ABN's environment (ABN press release).
- Data was staged and exfiltrated before or alongside the ransomware deployment (ABN press release).
- Suspicious activity predates the September 1 confirmation by up to several weeks (ABN press release).
ABN's remediation list includes "enhanced cybersecurity controls, advanced network monitoring tools, and additional credential authentication practices." Adding authentication controls often follows credential-based access such as stolen VPN or remote access credentials, or accounts without MFA. However, the board has not attributed the intrusion to compromised credentials, and this reading is analysis only. No threat actor, ransomware family, or indicators of compromise have been published.
What Organizations Should Do
- Require phishing-resistant MFA on all remote access. Cover VPN, RDP gateways, email and admin consoles. ABN's post-incident focus on authentication shows this is where it is commonly weak.
- Watch for data leaving the network, not only for encryption. Alert on unusual outbound volume, archive tools such as 7-Zip and WinRAR running on servers, and file sync or cloud transfer utilities like rclone. Data theft often happens days before ransomware is deployed.
- Store logs where attackers can't erase them. Send endpoint, authentication and firewall logs to immutable or off-network storage, so a ransomware deployment cannot destroy the evidence needed to work out the breach scope.
- Separate regulated data stores. Isolate systems that hold SSNs and PHI from general office networks, and limit which service accounts can bulk-query them.
- Plan manual fallbacks before you need them. ABN had to improvise paper intake and on-site collection. Agencies running critical licensing or credential systems should have tested offline procedures and an alternative verification path.
- Look into suspicious activity early. The gap between August anomalies and the September 1 confirmation shows the cost of slow triage. Set clear escalation timelines for unexplained authentication or network alerts.
Sources: Alabama Board of Nursing Addresses Cybersecurity Incident | Alabama Board of Nursing Reports Cybersecurity Incident and Potenti... | Alabama Board of Nursing recovering from cyberattack, offers paper... | Alabama's Nursing Board Is Still Rebuilding After a Sept. 1 Cyberat... | 80,000 Nurses Can't Renew Their Licenses After a Cyberattack Took D... | Alabama cyber incident disrupts nursing licensing | Alabama Appellate Courts probe possible C-Track data breach | Alabama Board of Nursing Data Breach: What Nurses & Public Need to...