CSIDB logo
Incident

Aroostook Mental Health Center

Incident posture

Attack window
Mar 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-17 06:56

Linked entities

Victim
Aroostook Mental Health Center
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Mar 2026
Discovered
Undetermined
Disclosed
Mar 2026
Resolved
Pending

Summary

Aroostook Mental Health Center, the largest behavioral healthcare provider in rural Maine, suffered a ransomware attack attributed to a Russian‑based cyber crime group that added the organization to its dark web leak site. The agency reported a network disruption, partnered with cyber incident specialists to investigate, and stated it chose not to negotiate with the attackers, while the scope of any data theft remained unclear. Services continued with limited interruptions as officials worked to restore systems and notify affected individuals.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

Aroostook Mental Health Center (AMHC) experienced a ransomware attack in March 2026, attributed to the Russia-based Qilin ransomware group, which added the organization to its dark web leak site on a Tuesday. The organization provides behavioral healthcare across Aroostook, Hancock and Washington counties with over 350 employees, 5,500 clients and 27 service locations. AMHC acknowledged the incident in a statement to the Bangor Daily News on Wednesday, describing a recent network disruption and noting engagement of cyber incident specialists to investigate. The exact timing of the initial compromise was not disclosed, as the agency noted it was unclear when the attack occurred.

The specific date of the intrusion and whether data were exfiltrated remain unknown, as AMHC declined to provide further specifics. Spokesperson Clare Hickey stated that the investigation is ongoing and that the appearance of the center’s name on Qilin’s leak site resulted from the decision not to negotiate with the attackers. The organization said it would update relevant parties as more information becomes available and would take all steps legally required.

Qilin operates as a ransomware‑as‑a‑service operation that began in 2022, is believed to originate from Russia, and had claimed responsibility for over 700 attacks in 2025 by late October. It made headlines in June 2024 for a ransomware attack on a UK pathology provider that disrupted more than ten thousand appointments and contributed to a fatality. The FBI’s 2024 Internet Crime Report recorded $16.6 billion in ransomware losses, a 33 % increase year‑over‑year.

Sources

Sources available to members: 1 source.

CSIDB