Nacogdoches Memorial Hospital
Incident posture
Linked entities
- Victim
- Nacogdoches Memorial Hospital
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Nacogdoches Memorial Hospital reported that a threat actor gained access to its internal network, compromising the personal and health information of approximately 250,000 individuals, including names, addresses, phone numbers, email addresses, Social Security numbers, dates of birth, medical record numbers, account numbers, health plan beneficiary numbers, and photographs. The hospital stated there is no evidence of misuse of the data, and after discovering the breach it resecured its network, strengthened security measures, and notified law enforcement. No details about the attacker have been disclosed, and no ransomware group has claimed responsibility. The facility, which provides emergency, cardiac, and surgical services, continues to operate while advising affected individuals to monitor their accounts for suspicious activity.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On January 31, 2026, a threat actor gained unauthorized access to Nacogdoches Memorial Hospital's internal network and information systems. The hospital discovered the intrusion shortly thereafter and immediately took steps to resecure its computer network. Following discovery, the hospital hardened its security controls and notified law enforcement agencies about the breach. In early April 2026, Nacogdoches Memorial Hospital informed the Maine Attorney General’s Office that the attackers likely accessed the personal and health information of approximately 257,073 individuals.
The potentially exposed data included names, addresses, phone numbers, email addresses, Social Security numbers, dates of birth, medical record numbers, account numbers, health plan beneficiary numbers, and photographs. The hospital stated in its notification letters that there was no evidence at that time that any of the compromised information had been misused. Affected individuals were advised to remain vigilant, monitor their financial and medical accounts for suspicious activity, and report any signs of identity theft or fraud. Nacogdoches Memorial Hospital clarified that it would not be providing free identity theft or credit monitoring services to those impacted.
As part of its response, the hospital confirmed that it had already resecured its network, implemented additional security hardening measures, and cooperated with law enforcement investigations. Nacogdoches Memorial Hospital did not disclose any details about the threat actor responsible for the incident, and no known ransomware group had claimed responsibility for the attack. The facility, which opened in December 1928 and operates a 226‑bed hospital offering emergency, cardiac, and surgical services, continued to provide care while addressing the breach. The notification effort reached roughly 250,000 people, reflecting the scale of the incident as communicated to the Maine Attorney General’s Office.
Sources
Sources available to members: 1 source.