CSIDB logo
Incident

New York Blood Center Enterprises

Incident posture

Attack window
Jan 2025
Location
United States of America
Status
Resolved
CIA posture
Available to members
Updated
2026-09-02 19:15

Linked entities

Victim
New York Blood Center Enterprises
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Jan 2025
Disclosed
Jan 2025
Resolved
Feb 2025

Summary

New York Blood Center Enterprises identified suspicious activity affecting its IT systems and engaged third‑party cybersecurity experts, who confirmed a ransomware incident; the organization took immediate containment steps, notified law enforcement, and worked with experts to restore systems. All operating divisions were affected to some extent, but blood collection activities have resumed, though some manual processes remain and inbound calling is disrupted at certain sites, while pharmacy, clotting factor, cryopreservation, PAT and clinical apheresis services continue as usual.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

On Sunday, January 26, 2025, New York Blood Center Enterprises detected suspicious activity affecting its information technology systems and promptly engaged third‑party cybersecurity experts to investigate. The investigation confirmed that the activity was a ransomware incident, prompting the organization to take immediate containment measures, including taking certain systems offline and notifying law enforcement. All operating divisions were affected to some extent, and the disruption led to the temporary suspension of normal in‑bound calling at Memorial Blood Centers and Nebraska Community Blood Bank, requiring donors to submit a General Inquiries form to be contacted by a representative. While some systems were isolated, the organization maintained direct communication with hospital partners and began implementing workarounds to help restore services and fulfill orders.

In response, New York Blood Center Enterprises worked continuously with the cybersecurity experts to restore its systems as quickly and safely as possible. By February 3, 2025, the organization reported that all blood collection activities had resumed across its operating divisions, including donor center operations and community blood drives, and it was working to reschedule any drives that had been cancelled. Although some manual processes remained in place and wait times could be longer than usual, essential services such as PAT and Clinical Apheresis continued at normal capacity, pharmacy services were able to process prescriptions and deliver orders, factor concentrate distribution remained unchanged, and the cellular therapy lab remained open for cryopreservation procedures and associated quality‑control testing. The organization expressed gratitude to its hospital partners, blood centers nationwide, the AABB Interorganizational Task Force, donors, and the broader blood and advanced therapy communities for their support during the incident.

Throughout the recovery period, New York Blood Center Enterprises continued to make strides toward returning to nearly normal distribution while acknowledging that sustained donor support remained essential to safeguard patient care. It encouraged eligible donors to give as soon as possible and invited community groups to host blood drives to help maintain a stable blood supply. The organization affirmed that it would remain in touch with its partners and provide updates as it progressed through the restoration effort.

Sources

Sources available to members: 1 source.

CSIDB