CSIDB logo
Incident

Mississippi Institutions of Higher Learning

Incident posture

Attack window
Sep 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-09-23 00:41

Linked entities

Victim
Mississippi Institutions of Higher Learning
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Feb 2026
Discovered
Undetermined
Disclosed
Mar 2026
Resolved
Pending

Summary

The Mississippi Institutions of Higher Learning experienced a cyberattack that disabled its Office of Student Financial Aid, halting the processing of student applications and payments while officials worked with federal law enforcement and cybersecurity experts to determine what data might have been accessed. The agency confirmed no ransom was paid and declined to detail its recovery progress. Separately, a ransomware incident hit the University of Mississippi Medical Center, disrupting its IT network, prompting clinic closures and the cancellation of elective procedures across the state; the medical center also stated no ransom was paid and noted an ongoing forensic analysis with FBI assistance. The state auditor later requested information from the agency's commissioner regarding both incidents, seeking details on scope, any extortion demands, payments made, and remediation plans.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On September 7, a cyberattack struck the Mississippi Institutions of Higher Learning offices, temporarily rendering the Mississippi Office of Student Financial Aid unable to process student applications and payments. IHL officials immediately began working with federal law enforcement and cybersecurity professionals to determine what happened and whether any confidential or sensitive data was accessed or compromised during the incident. IHL spokesperson John Sewell confirmed that the agency did not pay a ransom connected to the attack, although he noted that he could not yet share an update on the agency’s recovery process. The office remained focused on assessing the scope of the breach and coordinating with external experts to restore normal operations.

Earlier in February, a ransomware attack targeted the University of Mississippi Medical Center, compromising the health care system’s IT network and prompting officials to shut down affected systems to contain the threat. As a result, the state’s only academic medical center closed clinics across the state and canceled elective procedures for nine days while response efforts continued. UMMC officials, including spokesperson Marc Rolph, stated that the medical center did not pay a ransom to the hackers responsible for the incident. In April, officials reported that UMMC was conducting a detailed forensic analysis with support from the FBI and cybersecurity experts to determine what data was accessed or exfiltrated during the attack. The ransomware group Medusa claimed credit for the cyberattack in March, nearly a month after the initial shutdown, and demanded payment to prevent the publication of stolen data, although a UMMC spokesperson declined to confirm Medusa’s involvement. Louann Woodward noted in an April blog post that the perpetrator is well known to the FBI, underscoring the seriousness of the threat.

On Monday, State Auditor Shad White sent a letter to IHL Commissioner Al Rankins Jr. seeking more information about the agency’s response to both the September and February attacks. White requested details on the nature and scope of the incidents, whether a ransom or extortion payment was requested, information about any such payments, and copies of and plans for remediation. He wrote that taxpayers deserve to know what happens to their money and that the IHL should be transparent with what happened here.

Sources

Sources available to members: 1 source.

CSIDB