Cherry Health outage in Michigan investigated as possible cyberattack
The Grand Rapids-area provider says clinics remain open, but organizationwide technology issues have disrupted phones.
The Grand Rapids-area provider says clinics remain open, but organizationwide technology issues have disrupted phones.
The library system said some locations would reopen with limited services while public computers and printers remained unavailable.
Analysis, reports, and opinion that look beyond individual incidents. We examine trends, tactics, and sector-wide risks; connect dots across cases; and publish periodic research and explainers. Expect context, data-driven takeaways, and clear points of view to help readers understand what matters, why it happened, and what to watch next.
All in Analysis
What looked like scattered on-air pranks increasingly resembles a security problem rooted in exposed audio gear and old trust assumptions.
Energy, water and wastewater, transportation, communications, and financial systems that keep communities running. Coverage focuses on outages, service degradation, and operational risk from cyber incidents, sabotage, or vendor failures that disrupt essential services.
All in Critical Infrastructure
City officials said a March 14 attack hit a water treatment plant server, but the water supply stayed safe while staff ran manual procedures for about 16 hours.
Hospitals, clinics, public health agencies, payers, and health IT providers. We track incidents affecting patient care, ER diverts, EHR downtime, and PHI breaches, emphasizing operational impact, restoration status, and what patients and providers need to know.
All in Healthcare
Hospital says some emergency patients were transferred while imaging access was limited.
Public-facing city and county services other than critical infrastructure: 911/PSAP, EMS and fire, transit, libraries, housing, and social services. We report on outages, call routing issues, payment portals, and case-management systems that limit access to services.
All in Public Services
Affidavit says former employee used library credentials to remove security software, disrupting public computers
Federal, state, local, tribal, and territorial governments. Coverage focuses on operational impact, public notifications, restoration timelines, and risks to civic functions and records.
All in Government
Officials say the affected systems appear to have held only public information as the investigation continues and no restoration date has been announced.
K–12 districts, higher education, and community colleges. We cover closures, remote learning disruptions, SIS and E-Rate impacts, and breaches of student records. Vendor incidents land here when they disrupt teaching, learning, or campus operations.
All in Education
District officials said an outside actor accessed some systems, prompting a shutdown that canceled classes, child care and after-school programs Monday.
Companies and nonprofits whose incidents affect customers, supply chains, or communities. Includes MSPs, SaaS, media, retail, manufacturing, logistics, and insurers. Vendor events that disrupt hospitals, schools, or governments are cross-tagged but filed under the impacted sector.
All in Private Sector
Chevin said it took affected FleetWave environments offline in the U.S. and U.K. while it investigates the incident.