Skip to main content
Back to overview
Medium

University of Hawaiʻi Cancer Center Ransomware Attack and Data Breach

A ransomware attack on the University of Hawaiʻi Cancer Center's Epidemiology Division compromised the personal information of approximately 1.2 million individuals.

Key points

  • Ransomware attack targeted the Epidemiology Division servers.
  • Approximately 1.2 million individuals were affected.
  • Compromised data includes names, Social Security numbers, driver's license information, voter registration records, and health-related information.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Threat source not confirmed

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
Aug 31, 2025
Updated
Jun 25, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch ransomware, endpoint compromise and business interruption exposure.

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data

Mentioned entities

UhcancercenterData DisclosureUniversity of HawaiCancer Center Ransomware Attack andCancer CenterEpidemiology DivisionNotificationsRansomwareApproximatelyCompromised

Quick context

Questions about this signal

What happened in this signal?

A ransomware attack on the University of Hawaiʻi Cancer Center's Epidemiology Division compromised the personal information of approximately 1.2 million individuals. The stolen data includes names, Social Security numbers, driver's license information, voter registration records, and health-related information. The incident was discovered on August 31, 2025, and affected servers supporting research operations, though clinical operations, patient care, and student records were not impacted. The university engaged with the threat actors and paid a ransom to obtain decryption tools and assurances of data destruction. Notifications to affected individuals were delayed until early 2026.

When was this signal reported?

Shadow Tier lists Aug 31, 2025 as the signal date.

Which organization is connected to this signal?

Uhcancercenter is the organization connected to this public signal.

Explore Uhcancercenter
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence