Skip to content

Metro Pet Vet and Manheim Pike ransomware incident

Summary

Metro Pet Vet logo

Ransomware disrupted Metro Pet Vet and Manheim Pike Veterinary Hospital in Lancaster County, Pennsylvania, in January 2026, blocking access to a shared server and patient records at three clinics. Staff used paper records and a scheduling app while continuing urgent and scheduled care; data access or theft and the threat actor remain unresolved.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.

Primary victim organization

Organization types

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Scheduling disruption

    Appointment, booking, reservation, dispatch, staffing, or other scheduling functions were unavailable or impaired.

  • Healthcare operations disrupted

    Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Customer or public access restricted

    Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.

Extortion indicators

  • No known extortion indicator

    Available evidence indicates that no extortion demand, threat, communication, or related pressure tactic was identified.

Incident narrative

Analyst assessment

Our reporting and WGAL’s interview with owner and medical director Jeff Steed establish with high confidence that ransomware disrupted Metro Pet Vet and Manheim Pike Veterinary Hospital in January 2026. The ransomware blocked access to a shared server and patient records across the Manheim Pike, downtown Lancaster and Leola clinics.

Operational significance

Staff could not retrieve or update vaccine, medication and other patient histories. The clinics continued urgent and previously scheduled care using paper records and a scheduling app, but asked clients to limit calls while systems were unavailable.

The practice’s official notice said all locations were affected. Steed told WGAL that the compromised server did not store credit card or Social Security numbers, although it did contain client phone numbers and addresses. The public record does not establish that those records were accessed or stolen.

Confidence and uncertainty

Confidence is high that ransomware caused the records outage because the owner directly described ransomware being installed and the shared server becoming unavailable. No stable threat-actor or leak-site claim was located, and attribution remains unresolved.

Disclosure posture

Metro Pet Vet publicly described a cyberattack affecting all locations. The later owner interview provided the clearest public confirmation that the malware was ransomware and explained the manual workarounds.

Current status

The incident is presumed resolved. The practice expected temporary service limits to remain through the end of the week, and no continuing outage was located, but no final public all-clear established the precise restoration date.

Analytic gaps

The public record does not establish the initial access vector, vulnerability, malware family, threat actor, encryption scope, data-access or exfiltration scope, ransom demand or payment, law-enforcement involvement, restoration method or final recovery date.

Organizations involved

Impacted locations

Sources

Pennsylvania Metro Pet cyberattack limits vet visits

We reported records unavailability and service limits across the group’s Lancaster County clinics.

Cyberattack limits Lancaster County veterinary services

FOX43 reported the clinic’s cyberattack disclosure and inability to access pet medical records.

Fresh Face: Metro Pet Vet

Fig Lancaster described Metro Pet Vet as owned and operated by the team behind Manheim Pike Veterinary Hospital.

Our History

The practice says Manheim Pike Veterinary Hospital was founded in 1964 and identifies the Leola and downtown Lancaster clinics as later Metro Pet Vet expansions.

See something that needs correction?

Signed-in members can report an error, update, or missing source.