Cayuga Medical Center
Incident posture
Linked entities
- Victim
- Cayuga Medical Center
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
A cyberattack attempt against the medical center disrupted operations, prompting the hospital to issue a temporary diversion order that rerouted ambulances and paused emergency room admissions. Staff resorted to manual pencil-and-paper processes to check in patients while systems were taken offline for assessment and recovery. Critical cases such as strokes and severe heart attacks were diverted to other facilities as required by state protocol during such outages, with at least one ambulance redirected to a nearby hospital in Cortland. After approximately two and a half hours, the diversion order was lifted and the facility began admitting new patients again, though some systems remained offline as recovery efforts continued through the night. By the following morning, officials confirmed the hospital was fully operational and reported that the attempted breach had ultimately failed to penetrate the facility's systems.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On the evening of Tuesday, February 18, 2025, Cayuga Medical Center in Ithaca, New York, experienced an attempted cyberattack that disrupted a wide range of the hospital's computer systems and triggered a temporary diversion of emergency patients to other facilities. The diversion order was issued around 8:00 p.m. and remained in effect for approximately two hours and forty-five minutes, ending at roughly 10:45 p.m. During that window, ambulances were redirected away from Cayuga Medical Center, and the hospital paused emergency room admissions. Police scanner archives reviewed by local media documented an ambulance that was already en route to Cayuga Medical Center being redirected to a facility in Cortland as the diversion order was called. Patients arriving at the emergency department encountered a chaotic environment, with staff resorting to pencil-and-paper methods to check in new arrivals. At least several patients in the waiting room grew frustrated with the delays and left before being seen by clinical staff.
The nature and motive of the attempted cyberattack were not identified during the initial hours of the incident, and hospital representatives declined to speculate publicly about who was behind it or what method was used. According to CMC spokesperson Melissa Tourtellotte, the hospital isolated its systems in order to assess the situation as the disruption unfolded, a precaution consistent with containment practices when an intrusion or attempted intrusion is suspected. Tourtellotte confirmed that certain categories of patients—specifically those suffering strokes or ST-elevation myocardial infarction (STEMI), a severe form of heart attack—were diverted because state requirements mandate transfer to another facility during an outage of this nature. She also addressed concerns about a patient transfer that took place during the outage, stating that one individual was moved to another hospital but that the transfer had already been planned prior to the cyber incident and was unrelated to the system shutdown.
As of 11:30 p.m. on Tuesday night, Tourtellotte described the hospital as being in "recovery mode." While new patients could once again be admitted to the emergency room and ambulances were no longer being re-routed, portions of the hospital's computer systems remained offline while staff worked to bring them back into service. Tourtellotte indicated that all systems were expected to be restored later that same night, and that the hospital had successfully isolated the affected components before completing recovery procedures.
An update issued the following morning, Wednesday, February 19, 2025, confirmed that Cayuga Medical Center was fully operational. A hospital official stated that the attempted cyberattack had ultimately been unsuccessful at penetrating the hospital's systems, even though it caused operational difficulties and the temporary diversion described above. The combination of rapid system isolation, the multi-hour diversion order, and the subsequent overnight recovery allowed the hospital to avoid a confirmed intrusion while still suffering significant disruption to normal workflows, including downtime of electronic systems, manual fallback to paper-based processes, and the rerouting of time-sensitive emergency cases to neighboring hospitals.
Sources
Sources available to members: 1 source.