Claim details
Dark Project listed Mile Bluff Medical Center on August 5, 2026. External monitoring reported an allegation of roughly 500 GB stolen; Mile Bluff has not confirmed the actor attribution or claimed volume.
Mile Bluff Medical Center disclosed an April 2026 security event involving data encryption that disrupted phone and computer functions and forced clinical teams to use downtime procedures while patient care continued. A later breach notice said an unauthorized actor had accessed the network from March 18 through April 19 and copied files, while the electronic health record was not affected.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Unauthorized access to systems, accounts, networks, or data.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.
A service, system, platform, or operational capability remained available only in part or with significant limitations.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
DysruptionHub’s reporting on the April 22 incident said Mile Bluff Medical Center experienced a security event involving data encryption that disrupted some phone and computer functions. The hospital activated security protocols, engaged internal and third-party specialists, and shifted clinical teams to downtime procedures while continuing patient care. Mile Bluff described the operational impact as limited and temporary, but a pharmacy update also said several clinic prescription-dispensing sites would remain closed on April 22 while the Mauston location continued assisting patients.
Separately, DysruptionHub assesses with high confidence that the incident involved malicious unauthorized access and data compromise. Mile Bluff’s later data-privacy notice said it detected suspicious network activity on or about April 19 and determined that an unauthorized actor had access to its network between March 18 and April 19. The organization said the actor copied certain files, while its electronic health record was untouched. That later disclosure establishes unauthorized access and data exfiltration beyond the operational disruption documented in April.
Mile Bluff operates the only hospital in Juneau County and provides care across a broader central Wisconsin region. Its organization profile describes a 40-bed acute-care hospital alongside nursing and rehabilitation facilities, assisted living, a retirement community, pharmacy services and outreach medical centers. Disruption to phone and computer functions therefore affected a healthcare network with multiple service dependencies rather than a single administrative application.
The public record indicates that clinical care continued, but not under normal conditions. Staff moved to downtime procedures, some services were temporarily interrupted, and several clinic prescription-dispensing sites were closed on April 22. The reviewed sources do not establish ambulance diversion, emergency-department closure, interruption of the electronic health record, or a broad suspension of patient care.
Confidence is high that unauthorized network access and copied files occurred because Mile Bluff itself disclosed those findings. Confidence is also high that the April event caused operational disruption because the hospital publicly documented affected phone and computer functions and the use of downtime procedures.
Ransomware is assessed with high, but not confirmed, confidence. Mile Bluff described the incident as involving data encryption but did not publicly identify ransomware, a ransom demand or a specific malware family in the reviewed official notices. On August 5, the Dark Project extortion group listed Mile Bluff Medical Center on its leak site; external monitoring also reported the listing and an allegation that hundreds of gigabytes of data had been stolen. That claim is consistent with an extortion operation, but it is treated as threat-actor reporting rather than victim-confirmed attribution or proof of the claimed volume.
Mile Bluff said the potentially involved information varied by individual and could include names, Social Security numbers, driver’s-license numbers, financial-account information, medical information and health-insurance information. The organization was still conducting a comprehensive data review and had not yet finalized the affected population in the preliminary notice.
Mile Bluff’s April communications focused on operational continuity and described a security event involving data encryption, limited service interruptions and restoration work. The later privacy notice provided more specific forensic findings, including the March 18 to April 19 unauthorized-access window and confirmation that files were copied. The evolving disclosure materially narrows earlier uncertainty without establishing every technical detail or actor claim.
The latest reviewed operational evidence dates to April 22, when some pharmacy dispensing locations remained unavailable and restoration work was continuing. Later breach-administration and threat-actor developments do not establish continuing service disruption. Because more than 30 days have elapsed since the last documented operational impact and no final restoration notice was identified, the incident is assessed as presumed resolved rather than positively resolved.
The reviewed public sources do not establish the initial access vector, exploited vulnerability, compromised credentials, malware family, precise encryption scope, attacker dwell activity within the confirmed access window, ransom demand, payment status, or the exact number of affected individuals. Dark Project’s August claim has not been confirmed by Mile Bluff, and the claimed volume of stolen data remains unverified. Mile Bluff’s preliminary notice also leaves the final person-specific data scope unresolved pending completion of its review.
Dark Project listed Mile Bluff Medical Center on August 5, 2026. External monitoring reported an allegation of roughly 500 GB stolen; Mile Bluff has not confirmed the actor attribution or claimed volume.

Mile Bluff said a security event involving data encryption disrupted some phone and computer functions. Clinical teams shifted to downtime procedures while patient care continued, and a pharmacy-related update said clinic prescription-dispensing sites would remain closed on April 22 while the Mauston location remained available.
Mile Bluff said it became aware of suspicious network activity on or about April 19, 2026. Its investigation determined that an unauthorized actor accessed the network between March 18 and April 19 and copied certain files, while the electronic health record was untouched. Potentially involved information could include identifiers, financial, medical and health-insurance information.
Mile Bluff says it operates the only hospital in Juneau County, a 40-bed acute-care hospital, along with nursing and rehabilitation centers, assisted living, retirement housing, pharmacy services and five outreach medical centers serving a regional population.
RansomLook’s monitored Dark Project feed lists Mile Bluff Medical Center among the group’s August 5, 2026 victim posts. The listing establishes an actor claim but does not independently verify that Dark Project caused the April incident or the scope of any stolen data.
Comparitech reported that Mile Bluff Medical Center had been added to the leak site of the Dark Project ransomware group and that the group alleged roughly 500 GB of data was stolen. The allegation remains unconfirmed by Mile Bluff.
IRS-derived records identify Mile Bluff Medical Center Inc. in Mauston, Wisconsin, as a tax-exempt 501©(3) organization in the general hospital category that operates hospital facilities.
Signed-in members can report an error, update, or missing source.