Skip to content

Mile Bluff cyberattack disrupts systems and exposes data

Summary

Mile Bluff Medical Center logo

Mile Bluff Medical Center disclosed an April 2026 security event involving data encryption that disrupted phone and computer functions and forced clinical teams to use downtime procedures while patient care continued. A later breach notice said an unauthorized actor had accessed the network from March 18 through April 19 and copied files, while the electronic health record was not affected.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Impacted location

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Ransomware

    Malware that encrypts systems or data, typically accompanied by a ransom demand.

  • Unauthorized access

    Unauthorized access to systems, accounts, networks, or data.

Data impacts

  • Data theft or exfiltration

    Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.

  • Data encryption

    Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Phone service disruption

    Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.

  • Internal systems unavailable

    Internal business, administrative, operational, or staff-facing systems were unavailable.

  • Healthcare operations disrupted

    Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

Extortion indicators

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

Incident narrative

Analyst assessment

DysruptionHub’s reporting on the April 22 incident said Mile Bluff Medical Center experienced a security event involving data encryption that disrupted some phone and computer functions. The hospital activated security protocols, engaged internal and third-party specialists, and shifted clinical teams to downtime procedures while continuing patient care. Mile Bluff described the operational impact as limited and temporary, but a pharmacy update also said several clinic prescription-dispensing sites would remain closed on April 22 while the Mauston location continued assisting patients.

Separately, DysruptionHub assesses with high confidence that the incident involved malicious unauthorized access and data compromise. Mile Bluff’s later data-privacy notice said it detected suspicious network activity on or about April 19 and determined that an unauthorized actor had access to its network between March 18 and April 19. The organization said the actor copied certain files, while its electronic health record was untouched. That later disclosure establishes unauthorized access and data exfiltration beyond the operational disruption documented in April.

Operational significance

Mile Bluff operates the only hospital in Juneau County and provides care across a broader central Wisconsin region. Its organization profile describes a 40-bed acute-care hospital alongside nursing and rehabilitation facilities, assisted living, a retirement community, pharmacy services and outreach medical centers. Disruption to phone and computer functions therefore affected a healthcare network with multiple service dependencies rather than a single administrative application.

The public record indicates that clinical care continued, but not under normal conditions. Staff moved to downtime procedures, some services were temporarily interrupted, and several clinic prescription-dispensing sites were closed on April 22. The reviewed sources do not establish ambulance diversion, emergency-department closure, interruption of the electronic health record, or a broad suspension of patient care.

Confidence and uncertainty

Confidence is high that unauthorized network access and copied files occurred because Mile Bluff itself disclosed those findings. Confidence is also high that the April event caused operational disruption because the hospital publicly documented affected phone and computer functions and the use of downtime procedures.

Ransomware is assessed with high, but not confirmed, confidence. Mile Bluff described the incident as involving data encryption but did not publicly identify ransomware, a ransom demand or a specific malware family in the reviewed official notices. On August 5, the Dark Project extortion group listed Mile Bluff Medical Center on its leak site; external monitoring also reported the listing and an allegation that hundreds of gigabytes of data had been stolen. That claim is consistent with an extortion operation, but it is treated as threat-actor reporting rather than victim-confirmed attribution or proof of the claimed volume.

Mile Bluff said the potentially involved information varied by individual and could include names, Social Security numbers, driver’s-license numbers, financial-account information, medical information and health-insurance information. The organization was still conducting a comprehensive data review and had not yet finalized the affected population in the preliminary notice.

Disclosure posture

Mile Bluff’s April communications focused on operational continuity and described a security event involving data encryption, limited service interruptions and restoration work. The later privacy notice provided more specific forensic findings, including the March 18 to April 19 unauthorized-access window and confirmation that files were copied. The evolving disclosure materially narrows earlier uncertainty without establishing every technical detail or actor claim.

Retrospective note

The latest reviewed operational evidence dates to April 22, when some pharmacy dispensing locations remained unavailable and restoration work was continuing. Later breach-administration and threat-actor developments do not establish continuing service disruption. Because more than 30 days have elapsed since the last documented operational impact and no final restoration notice was identified, the incident is assessed as presumed resolved rather than positively resolved.

Analytic gaps

The reviewed public sources do not establish the initial access vector, exploited vulnerability, compromised credentials, malware family, precise encryption scope, attacker dwell activity within the confirmed access window, ransom demand, payment status, or the exact number of affected individuals. Dark Project’s August claim has not been confirmed by Mile Bluff, and the claimed volume of stolen data remains unverified. Mile Bluff’s preliminary notice also leaves the final person-specific data scope unresolved pending completion of its review.

Threat actor and claim

Listed as: Mile Bluff Medical CenterSource: otherPublished:

Claim details

Dark Project listed Mile Bluff Medical Center on August 5, 2026. External monitoring reported an allegation of roughly 500 GB stolen; Mile Bluff has not confirmed the actor attribution or claimed volume.

Organizations involved

Impacted location

Sources

Mile Bluff Medical Center in Wisconsin says security event disrupted phone, computer systems

Mile Bluff said a security event involving data encryption disrupted some phone and computer functions. Clinical teams shifted to downtime procedures while patient care continued, and a pharmacy-related update said clinic prescription-dispensing sites would remain closed on April 22 while the Mauston location remained available.

Mile Bluff Medical Center - Notice of Data Privacy Event

Mile Bluff said it became aware of suspicious network activity on or about April 19, 2026. Its investigation determined that an unauthorized actor accessed the network between March 18 and April 19 and copied certain files, while the electronic health record was untouched. Potentially involved information could include identifiers, financial, medical and health-insurance information.

About Mile Bluff Medical Center

Mile Bluff says it operates the only hospital in Juneau County, a 40-bed acute-care hospital, along with nursing and rehabilitation centers, assisted living, retirement housing, pharmacy services and five outreach medical centers serving a regional population.

Dark Project

RansomLook’s monitored Dark Project feed lists Mile Bluff Medical Center among the group’s August 5, 2026 victim posts. The listing establishes an actor claim but does not independently verify that Dark Project caused the April incident or the scope of any stolen data.

Mile Bluff Medical Center added to Dark Project leak site

Comparitech reported that Mile Bluff Medical Center had been added to the leak site of the Dark Project ransomware group and that the group alleged roughly 500 GB of data was stolen. The allegation remains unconfirmed by Mile Bluff.

Mile Bluff Medical Center Inc

IRS-derived records identify Mile Bluff Medical Center Inc. in Mauston, Wisconsin, as a tax-exempt 501©(3) organization in the general hospital category that operates hospital facilities.

See something that needs correction?

Signed-in members can report an error, update, or missing source.