Menu
Browse

Cyber Incident Victim: McKenzie Health System

Date:

Apr 2025

Location:

United States of America

Summary

McKenzie Memorial Hospital experienced an external system breach resulting from hacking that compromised the personal information of approximately fifty‑four thousand individuals, including six residents of Maine. The breach was later discovered and affected individuals received written notification offering twelve months of credit monitoring and identity theft protection through TransUnion.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 0 motives 0 techniques
Threat Actors Type Location
0 actors Available to members Available to members

Description

On April 14, 2025, McKenzie Memorial Hospital experienced an external system breach that was characterized as a hacking incident. The breach remained undetected until June 19, 2025, when the hospital’s security team discovered the unauthorized access. According to the breach notification filed with the Maine Attorney General, the incident compromised the personal information of 54,016 individuals, of whom six were residents of Maine. The notification did not specify the exact data elements that were compromised. The hospital’s location is listed as 120 Delaware Street, Sandusky, MI 48471.

Cyber Incident Image

Following discovery, the hospital arranged for written notification to be sent to all affected individuals, with the mailing date set for July 24, 2025. The notification informed recipients of the breach and offered them the opportunity to enroll in identity theft protection services. As part of the response, McKenzie Memorial Hospital provided twelve months of credit monitoring and identity theft protection through TransUnion at no cost to those who chose to participate. The offer was described in the notification as a protective measure for individuals wishing to mitigate potential misuse of their data. The breach notification was submitted by Amanda A. Ruggieri, counsel for the hospital, representing the law firm Cipriani & Werner, PC. No further details about the attacker’s methods or the specific systems involved were disclosed in the available source.

Sources
Sources available to members
1 source