CSIDB logo
Incident

Nacogdoches Memorial Hospital

Incident posture

Attack window
Jan 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 09:29

Linked entities

Victim
Nacogdoches Memorial Hospital
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Jan 2026
Discovered
Undetermined
Disclosed
Apr 2026
Resolved
Pending

Summary

Nacogdoches Memorial Hospital reported that a threat actor gained access to its internal network, compromising the personal and health information of approximately 250,000 individuals, including names, addresses, phone numbers, email addresses, Social Security numbers, dates of birth, medical record numbers, account numbers, health plan beneficiary numbers, and photographs. The hospital stated there is no evidence of misuse of the data, and after discovering the breach it resecured its network, strengthened security measures, and notified law enforcement. No details about the attacker have been disclosed, and no ransomware group has claimed responsibility. The facility, which provides emergency, cardiac, and surgical services, continues to operate while advising affected individuals to monitor their accounts for suspicious activity.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

1 technique

Description

On January 31, 2026, a threat actor gained unauthorized access to Nacogdoches Memorial Hospital's internal network and information systems. The hospital discovered the intrusion shortly thereafter and immediately took steps to resecure its computer network. Following discovery, the hospital hardened its security controls and notified law enforcement agencies about the breach. In early April 2026, Nacogdoches Memorial Hospital informed the Maine Attorney General’s Office that the attackers likely accessed the personal and health information of approximately 257,073 individuals.

The potentially exposed data included names, addresses, phone numbers, email addresses, Social Security numbers, dates of birth, medical record numbers, account numbers, health plan beneficiary numbers, and photographs. The hospital stated in its notification letters that there was no evidence at that time that any of the compromised information had been misused. Affected individuals were advised to remain vigilant, monitor their financial and medical accounts for suspicious activity, and report any signs of identity theft or fraud. Nacogdoches Memorial Hospital clarified that it would not be providing free identity theft or credit monitoring services to those impacted.

As part of its response, the hospital confirmed that it had already resecured its network, implemented additional security hardening measures, and cooperated with law enforcement investigations. Nacogdoches Memorial Hospital did not disclose any details about the threat actor responsible for the incident, and no known ransomware group had claimed responsibility for the attack. The facility, which opened in December 1928 and operates a 226‑bed hospital offering emergency, cardiac, and surgical services, continued to provide care while addressing the breach. The notification effort reached roughly 250,000 people, reflecting the scale of the incident as communicated to the Maine Attorney General’s Office.

Sources

Sources available to members: 1 source.

CSIDB