CSIDB logo
Incident

Sault Ste. Marie Tribe of Chippewa Indians

Incident posture

Attack window
Feb 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 14:12

Linked entities

Victim
Sault Ste. Marie Tribe of Chippewa Indians
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Feb 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A cyberattack targeted the Sault Ste. Marie Tribe of Chippewa Indians, disrupting tribal government operations, healthcare services, pharmacies, gas stations, casinos, and hotels, while also taking down phone lines and canceling events. Upon discovery of the incident, the tribe engaged the FBI to investigate and declined to pay the ransom demanded by the cybercriminals, a decision made in consultation with cybersecurity experts, legal counsel, and law enforcement. The tribe's chairman publicly apologized for the disruption and announced efforts to strengthen IT systems and expand cybersecurity training for employees. Most operations were eventually restored, though the healthcare division remained affected, and the tribe is conducting a forensic audit involving manual review of hundreds of thousands of documents to determine what personal information may have been stolen.

Motives

Detailed motive labels are available to members.

2 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On February 9, 2025, the Sault Ste. Marie Tribe of Chippewa Indians became aware that it had been the victim of a cyberattack. The intrusion caused widespread disruption across the tribe's operations, including limited tribal government services, the closure of gas stations, casinos, and hotels, the cancellation of events, downed phone lines, and the restructuring of healthcare services and pharmacies. The attack had a particularly significant impact on the tribe's health care division, which was the most affected sector. In late February, tribal Chairman Austin Lowes publicly apologized for how disruptive the incident had been and stated that the tribe was working to strengthen its IT systems and expand cybersecurity training for employees. A spokesperson for the tribe confirmed February 9 as both the date the attack occurred and the date the tribe became aware of it, while also noting that the investigation remained active with the FBI, leaving some details unclear.

In response to the attack, the tribe announced that it would not pay the ransom demanded by the cybercriminals. Chairman Lowes explained this decision in a recorded video released on March 5, stating that the choice was made in consultation with cybersecurity experts, legal counsel, and law enforcement. Lowes emphasized that the tribe did not trust the attackers to keep their word, noting that even if the ransom were paid, the criminals could still have leaked the stolen data. By the time of reporting in late March, the tribe had restored most of its operations, though phone numbers for various health services were still being posted on the tribe's Facebook page as of March 12, indicating that the healthcare division had not yet fully recovered. The tribe also began conducting a forensic audit to determine what information had been stolen, a process described as lengthy and requiring the tribe's IT team to manually review hundreds of thousands of documents.

The tribe committed to reaching out directly to members and employees if their personal data was found to have been compromised, but encouraged individuals not to wait for that notification to take protective measures. Recommendations communicated through the reporting included contacting credit card providers to set up fraud alerts, changing passwords, and requesting a credit freeze through one of the three major credit reporting agencies. The tribal police department and the FBI did not respond to requests for comment from the media at the time of the report, and the investigation into the full scope of the breach continued as an active matter.

Sources

Sources available to members: 1 source.

CSIDB