University of Hawaiʻi Cancer Center
Incident posture
Linked entities
- Victim
- University of Hawaiʻi Cancer Center
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A ransomware attack compromised the personal information of approximately 1.2 million individuals associated with the University of Hawaiʻi Cancer Center. The breach affected research servers, leaving clinical operations and patient care unaffected, and exposed names, Social Security numbers, driver’s license details, voter registration records, and for some participants in a long‑running study, health‑related information. The institution engaged the threat actors to obtain a decryption tool and confirm destruction of exfiltrated data, though the ransom amount was not disclosed, and is offering affected individuals twelve months of free credit monitoring and identity theft services while the investigation continues with law enforcement support.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On August 31, 2025, a ransomware attack targeted the servers that support the research operations of the University of Hawaiʻi Cancer Center, leading to the encryption of data and the compromise of personal information belonging to approximately 1.2 million individuals. The university’s incident notice described the extensiveness of the encryption by the threat actors as making it difficult to restore the affected systems and to assess the full scope of the compromised data. The attack did not affect the center’s clinical operations, patient care, or any other divisions of the UH Cancer Center, and it had no impact on University of Hawaiʻi student records. The university confirmed that the breach was limited to research‑related systems and did not involve any clinical trial databases.
The majority of the compromised data originated from a long‑running study that was established in 1993 and recruited more than 215,000 participants between 1993 and 1996. Records of 87,493 of those study participants were exposed, containing names, Social Security numbers, and, for some individuals, additional research‑related and health information. In addition to the study data, the names, driver’s license details, Social Security numbers, and voter registration records of roughly 1.15 million people were also compromised in the incident. The university emphasized that no information held by the Clinical Trials operations or patient care divisions was affected by the ransomware.
To address the breach, the University of Hawaiʻi engaged with the threat actors in an effort to protect the individuals whose sensitive information may have been exposed, and it obtained a decryption tool that allowed the restoration of the encrypted systems. The institution also ensured that any exfiltrated data was destroyed, although it did not disclose any details about a ransom payment. As part of its response, the university is providing the affected individuals with twelve months of free credit monitoring and identity theft services. The investigation into the breach remains ongoing, with the university working alongside law enforcement agencies and cybersecurity experts to determine whether any additional information was compromised.
The university published an incident notice last week, detailing the extent of the encryption and the steps taken to address the breach. In that notice, the institution stated that it obtained a decryption tool from the threat actors and confirmed the destruction of any exfiltrated data. The notice also affirmed that the university would continue to work with law enforcement and cybersecurity experts to investigate any further compromise.
Sources
Sources available to members: 1 source.