Cyber & AI intelligence
Wasteland.
Briefs indexed2781
Issues28
Published Mondays07:30 CT
█ Ransomware UMMC-FEBRUARY-CYBE 2026-09-21

University of Mississippi Medical Center: Medusa Ransomware Disruption With No Ransom Paid

"Seven months after a February 19, 2026 cyberattack knocked the University of Mississippi Medical Center's clinical and administrative systems offline, the Jackson-based academic medical center has publicly confirmed it…"

Seven months after a February 19, 2026 cyberattack knocked the University of Mississippi Medical Center's clinical and administrative systems offline, the Jackson-based academic medical center has publicly confirmed it paid the attackers nothing. UMMC Vice Chancellor for Health Affairs LouAnn Woodward, MD, told SuperTalk Mississippi on September 17 that the state did not compensate the hackers, and State Sen. Nicole Akins Boyd, who chairs the Senate Universities and Colleges Committee, corroborated that account. The statements came after State Auditor Shad White said his office would investigate the incident and tell the public if taxpayer money had gone to a ransom. The attack took down phones, the public website, the records database and broader IT infrastructure at Mississippi's only Level I trauma center, forced clinicians onto pen and paper, and closed partner clinics for nine days before full operations resumed February 27.

What Happened

Accounts across the reporting are consistent on the shape of the outage and differ mainly in how they count the days. Becker's Hospital Review and SuperTalk Mississippi both report that the February 19 attack hit UMMC's phones, website, records database and IT systems, that partner clinics shut down for nine days, that staff recorded patient information by hand, and that the medical center was cleared to return to full operations on February 27. Omnissa's write-up describes the same event as a ransomware attack that took UMMC's Epic electronic medical record system offline and closed 35 clinics across the state, and says it took "over a week" to bring those clinics back. Contemporaneous coverage aggregated by 7daweb and the LWV Jacksonville League piece adds that all 35 UMMC health clinics closed, affecting services from cancer treatment to chronic pain management, and that Woodward said all IT systems were deliberately taken down as a precaution while a comprehensive risk assessment guided the phased restoration.

Emergency departments and inpatient units stayed open throughout. Elective procedures, imaging appointments, and some chemotherapy and dialysis sessions were canceled, per Omnissa. A senior FBI official in Mississippi indicated the bureau was surging resources locally and nationally, and Mississippi Today reporting summarized by Headtopics confirms the FBI and outside cybersecurity experts joined the response. The Mississippi Independent reports that the Department of Homeland Security also participated in the recovery.

Attribution remains one step short of confirmed by the victim. Reporting relayed by Headtopics states that the ransomware group Medusa claimed credit in March, nearly a month after the attack, and demanded payment to prevent publication of stolen data. UMMC spokesperson Patrice Guilfoyle did not respond to questions about whether Medusa was in fact the group responsible. The Mississippi Independent, citing Lt. Gov. Delbert Hosemann, describes the attacker as a ransomware group that security researchers link to Russia and puts the demand at $800,000. That figure appears in only one source and should be treated as attributed rather than established; no source publishes a demand figure sourced directly to UMMC.

What Was Taken

This is the part nobody has closed out. As of the most recent reporting, UMMC has not said publicly whether patient data was stolen. Mississippi Today reported in early September that the medical center was still conducting a detailed forensic analysis with FBI and third-party support to determine what data was accessed or exfiltrated, and that UMMC would meet all regulatory and reporting requirements once that investigation concludes. Guilfoyle declined to answer whether patient data was taken.

What is on the record is that the extortion side of the incident was data-driven rather than purely encryption-driven: the group claiming the attack demanded payment to suppress publication of stolen data, which implies exfiltration occurred or was claimed to have occurred. No source reports a victim count, a record count, or a completed HIPAA breach notification for this incident. Anyone quoting a number for UMMC February 2026 right now is quoting something these sources do not contain.

For scale context on what a Mississippi health system breach can mean, the Mississippi Independent notes the 2023 ransomware attack on Singing River Health System in Ocean Springs exposed the health information of nearly a million people, and that UMMC itself paid $2.75 million in federal fines after a 2013 laptop theft exposed roughly 10,000 patient records, with federal investigators finding the center had known of the underlying vulnerability since 2005.

Why It Matters

The no-ransom confirmation is the story, and it is a useful one for defenders arguing the same case internally. UMMC is not a small target that could afford to ride out an outage quietly. It is Mississippi's largest hospital, its only Level I trauma center, its only children's hospital and its only organ transplant program, running on roughly a $2 billion budget that by UMMC's own materials accounts for about 2% of the state's economy, and treating more than 70,000 patients a year. It took an eight to nine day hit to clinic operations, ran a statewide clinical network on paper, and still restored service without paying. That is a concrete counterexample to the "we had no choice" argument executives reach for under pressure, and it aligns with FBI and CISA guidance that payment funds the next attack and does not guarantee recovery.

The verification layer matters as much as the claim. A state auditor publicly committing to trace whether public money moved to a ransomware crew, and to disclose the dollar amount if it did, is an unusually concrete accountability mechanism for a public hospital breach. White explicitly separated what will stay private from what will not: "We may never know the exact mechanism that the hackers used to get in, for good reason. But we will ultimately know what that dollar amount was."

The clinical risk is not theoretical. Omnissa cites a Halcyon study finding in-hospital mortality rises by roughly a third during a ransomware incident. Nine days of paper charting across 35 clinics is a patient safety event, not just an IT event.

Finally, this was a policy trigger. Hosemann has created a Senate Select Committee on Cybersecurity to study state and local government system security and review how Mississippi prosecutes cybercrime, citing UMMC as the most severe recent case. The Mississippi Independent notes UMMC was the fourth Mississippi hospital system hit in three years, after Singing River, North Mississippi Health Services and OCH Regional Medical Center in Starkville, and that the state has no law requiring hospitals to defend against cyberattacks; only HIPAA imposes that duty, and only the federal government enforces it. The auditor is separately reviewing a cyberattack on the Mississippi Institutions of Higher Learning, which governs UMMC and saw its student financial aid office affected.

The Attack Technique

The initial access vector has not been disclosed, and the auditor has signaled it may never be. The one substantive technical statement from UMMC is a negative: "What we do know is the Feb. 19 cyberattack was not the result of a single user error or someone clicking on a malicious email," Guilfoyle said, adding that "our monitoring systems and recovery protocols worked as designed, enabling us to stop the intrusion quickly and return largely back to normal significantly faster than the national average for recovery from similar incidents."

Read carefully, that rules out simple phishing-to-endpoint as the whole story and points toward something on the infrastructure or credential side, which is consistent with how Medusa affiliates typically operate: exploitation of internet-facing services and unpatched edge infrastructure, or valid-account abuse, followed by lateral movement, exfiltration and encryption under a double-extortion model. That characterization is inference from the group's known tradecraft, not something any of these sources states about this intrusion.

The one systemic angle the sources do raise is patching. Omnissa frames the UMMC Epic outage as an illustration of regulated industries running the least-patched device fleets, noting that a hospital environment includes bedside monitors, medication carts, handheld scanners and clinician tablets that receive far less security attention than core network infrastructure. Treat that as vendor commentary with a thesis attached, but the underlying observation about healthcare device patch debt is well supported elsewhere.

UMMC's own defensive takeaway is the containment decision: pulling all IT systems down deliberately and restoring in phases behind a risk assessment. That is an expensive call that trades days of clinical disruption for containment certainty, and it is the call that made the eight-day recovery and the no-payment outcome possible.

What Organizations Should Do

  1. Decide the payment question before the incident, in writing. UMMC's ability to say "no" publicly, months later, with the auditor watching, came from having a defensible position. Get board-level sign-off on a no-pay default and on the narrow conditions under which it would be revisited, so the decision is not made at 3 a.m. by whoever is on the bridge call.

  2. Rehearse the full-shutdown containment play, not just failover. UMMC took everything down, including phones and the public website, and brought it back under a formal risk assessment. If your runbook assumes partial isolation, test the scenario where you cannot trust any segment and have to restore from a known-good baseline outward.

  3. Build downtime procedures that survive nine days, not nine hours. Paper charting, manual order entry, lab and imaging result routing, medication reconciliation, and the reconciliation backlog when the EMR returns all need to work at week scale across every site, including partner clinics. Drill the re-entry, which is where the data integrity and billing damage usually lands.

  4. Assume exfiltration and preserve for it. The extortion here was publication-based. Ensure egress logging, DLP telemetry and netflow retention are long enough and complete enough that a forensic team can actually answer "what left" without a seven-month gap, and stand up a notification plan that does not depend on the attacker's leak site as the source of truth.

  5. Close the patch gap on edge infrastructure and clinical devices. Prioritize internet-facing VPN, file transfer, remote access and hypervisor management surfaces first, then work the clinical device fleet that conventional patch programs skip. Inventory is the prerequisite; you cannot patch what is not on the list.

  6. Enforce phishing-resistant MFA and segment the identity plane. Valid-account abuse remains the most common path to a hospital-wide encryption event. Separate administrative identities from clinical ones, eliminate standing domain admin, and monitor for the credential-to-lateral-movement sequence rather than only for malware signatures.

  7. Keep offline, immutable, tested backups for the EMR and everything it depends on. The recovery speed UMMC claims is only achievable when restore paths are validated in advance, including the dependency chain of directory services, interfaces and integration engines that the EMR needs to come back up.

Sources: UMMC Says It Paid No Ransom in February Cyberattack Healthcare Tec... | UMMC officials say no ransom was paid in February cyberattack | No ransom was paid in response to February cyberattack on Universit... | Months after UMMC cyberattack, questions persist about patient data... | New cybersecurity committee follows years of attacks without preven... | Why regulated industries run the least patched devices - Omnissa | Major Cyberattack Forces Closure of Clinics Across Mississippi (2026) | Mississippi Health Care System Shuts Down Clinics Due to Massive Ra...