Menu
Browse

Cyber Incident Victim: Cameron Regional Medical Center

Date

Jun 2026

Location

United States of America

Status

Ongoing

Updated

2026-08-19 07:19

Timeline
Occurred
Undetermined
Discovered
Jun 2026
Disclosed
Aug 2026
Resolved
Pending
Summary

Cameron Regional Medical Center confirmed a ransomware attack after discovering the breach and receiving a claim of responsibility from the Anubis group on the dark web. The attackers allegedly accessed patient records, employee information, internal investigations, HIPAA documents and other sensitive healthcare data, potentially exposing names, addresses, Social Security numbers, financial details and medical information. The hospital stated it has not seen evidence of fraudulent misuse but noted the investigation is ongoing and that affected individuals will be notified by mail. An incident response team has been established to handle inquiries.

CIA Posture Motives Tactics, Techniques & Procedures
Available to members 1 motive 1 technique
Threat Actor Type Location
1 actor Available to members Available to members

Description

Cameron Regional Medical Center discovered a ransomware attack on June 18, 2026, after noticing unusual activity on its systems. The hospital later confirmed the incident following claims posted on the dark web by a ransomware group known as Anubis, which asserted responsibility on August 3, 2026. Anubis stated it had obtained a wide range of data from the medical center and threatened to publish the stolen information within six days of its posting. The hospital’s own investigation into the breach remained ongoing at the time of the public notice, and it had not been able to determine the exact information that may have been accessed.

Cyber Incident Image

The types of personally identifiable information potentially exposed included patient names, addresses, dates of birth, Social Security numbers, driver’s license numbers, financial account information, electronic or digital signatures, and employer‑assigned identification numbers. Protected health information potentially compromised covered medical diagnosis and treatment information, dates of medical treatment, medical provider names, patient identification numbers, agency‑assigned identification numbers, treatment cost information, and health insurance information. The hospital noted that it was unable to confirm the specific information that may have been affected and stated that affected individuals would receive written notification via U.S. Mail. At the time of the notice, the hospital said it was not aware of any evidence suggesting fraudulent misuse of the data, but it also acknowledged that it had not yet been able to ascertain whether such attempts had occurred.

In response, Cameron Regional Medical Center indicated that it had existing security measures and facilities that had previously been audited. The hospital established an Incident Response Team to handle inquiries about the incident, reachable by phone at 816‑614‑1141 or in writing at 1600 E. Evergreen St., Cameron, MO 64429. The notice emphasized that the hospital takes the privacy and security of the information in its care seriously and regrets any worry or inconvenience caused by the incident. No offer of free credit monitoring or identity protection services was included in the notification.

Sources
Sources available to members
1 source