CSIDB logo
Incident

University of California, San Francisco

Incident posture

Attack window
Jun 2020
Location
United States of America
Status
Historical
CIA posture
Available to members
Updated
2026-06-18 08:39

Linked entities

Victim
University of California, San Francisco
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Jun 2020
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

The University of California, San Francisco paid a $1.14 million ransom to the Netwalker ransomware group after attackers encrypted servers within its School of Medicine, disrupting academic work but not affecting COVID-19 research, patient care, or medical records. Following negotiations on the dark web, which began with an initial offer of $780,000, the institution paid to obtain a decryption tool and worked with external experts to restore affected systems, while the attackers leveraged media attention to pressure victims despite advisories against ransom payments.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On June 1, 2020, attackers encrypted servers within the University of California San Francisco’s School of Medicine, disrupting access to academic research data. The Netwalker ransomware group claimed responsibility for the attack, which specifically targeted a limited number of servers but did not impact COVID-19 research projects, patient medical records, or clinical operations at the affiliated UCSF Medical Center. Following the encryption, UCSF engaged in negotiations with the attackers through a dark web chat channel, initially offering $780,000 for a decryption tool. The attackers ultimately demanded and received a $1.14 million ransom payment, which the university paid to regain access to its encrypted data. The BBC reported observing these negotiations in real time through an anonymous tip, publishing excerpts of the chat exchanges where the criminals pressured the institution.

UCSF confirmed the payment on June 26, 2020, stating the decryption process was underway with assistance from external cybersecurity experts. The university emphasized that no patient care systems were compromised and that the affected servers primarily contained academic research data critical to public health initiatives. Netwalker, identified by security researchers as a group that ignored voluntary bans on targeting healthcare entities during the pandemic, employed media attention as leverage, with the BBC’s coverage amplifying pressure on UCSF during negotiations. The university restored the encrypted servers following the payment but did not disclose whether backups were available or utilized in the recovery process. Cybersecurity analysts noted this incident exemplified ransomware groups’ evolving tactics of publicizing attacks to coerce victims into paying ransoms despite official advisories against such payments.

Sources

Sources available to members: 2 sources.

CSIDB