Skip to content

Signature Healthcare cybersecurity incident

Summary

Signature Healthcare Corporation logo

Signature Healthcare detected suspicious network activity on April 6, 2026, and shifted affected Massachusetts operations to downtime procedures. Brockton Hospital diverted ambulances, chemotherapy appointments were canceled, pharmacies could not fill prescriptions and electronic records services were impaired before staged restoration concluded later in April.

Key facts

Timeline

  • Incident start:
    ? Earliest known or assessed start of malicious activity or incident activity.
  • First public signal:
    ? Earliest public indication of an outage, disruption, closure or other observable incident impact. The signal does not need to mention cybersecurity.
  • First public cyber evidence:
    ? Earliest credible public information connecting the incident or disruption to malicious cyber activity.
  • Official cyber disclosure:
    ? First official acknowledgment by the affected organization or an authoritative public body that the incident was cyber-related.
  • Last impact seen:
    ? Latest public indication that disruption, degraded operations, recovery work or unresolved impact was still ongoing.
  • Incident end:
    ? Confirmed or defensibly assessed end of material operational disruption or incident activity.

Primary victim organization

Critical infrastructure sector

Incident characteristics

Assessments

DD-CIT assessment

The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.

Attack mechanisms

  • Unknown cyber mechanism

    The incident is confirmed to be cyber-related, but the specific attack mechanism is unknown.

Data impacts

  • Data unavailable

    Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.

Operational impacts

  • Partial service outage

    A service, system, platform, or operational capability remained available only in part or with significant limitations.

  • Online portal unavailable

    A public, customer, employee, student, patient, vendor, or partner portal was unavailable or materially impaired.

  • Records access disruption

    Staff, customers, patients, students, residents, or other users could not access records or case information normally.

  • Healthcare operations disrupted

    Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.

  • Event or activity cancellation

    Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.

  • Service delay

    Services continued but with longer processing, response, delivery, or completion times.

  • Backlog created

    The disruption caused an accumulation of unprocessed requests, cases, orders, records, appointments, or other work.

  • Manual workaround required

    Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.

  • Alternate service channel required

    The organization redirected users to a different website, office, telephone number, email address, provider, or service channel.

Extortion indicators

  • Ransom demand

    The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.

  • Data-theft extortion

    The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.

  • Public leak threat

    The actor explicitly threatened to publish or publicly release victim data or incident details.

  • Leak-site listing

    The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.

  • Countdown or payment deadline

    The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.

Incident narrative

Analyst assessment

Signature Healthcare detected suspicious activity in certain information systems April 6, 2026, took systems offline and shifted affected operations to downtime procedures. Our reporting documented ambulance diversion, canceled chemotherapy, pharmacy limitations, electronic-record and portal outages, delayed appointments and paper workflows. DysruptionHub assesses with high confidence that a confirmed cyber incident materially disrupted the health system because Signature directly described both the cyber-specific event and its operational consequences.

Operational significance

The most severe effects were at Signature Healthcare Brockton Hospital, where ambulances were diverted and some chemotherapy appointments were canceled. Signature’s official alerts also said information systems within the health system were affected and that Signature Medical Group and urgent-care practices remained open but patients could experience delays. The official location directory places those practices in Brockton, East Bridgewater, Bridgewater, Easton, Raynham and Stoughton. The four municipalities not already represented are therefore included as medium-confidence impacted locations: the systemwide practice impact is documented, although the alerts do not enumerate the exact disrupted function at every individual site.

Disclosure posture

Signature publicly acknowledged the cybersecurity incident and suspicious activity April 6. Anubis posted a leak-site claim April 9 alleging theft of about 2 TB and issuing an extortion deadline. Because the affected organization used cyber-specific language first, the disclosure sequence supports OC rather than XC-OC. The actor claim remains external and unverified; Signature has not attributed the incident to Anubis or confirmed ransomware, encryption, a ransom demand or data theft.

Current status

The documented operational disruption is resolved. Signature’s April alerts record staged restoration, including hospital and practice services and the return of pharmacy operations by April 24. No later continuing service impact was found.

Confidence and uncertainty

Confidence is high in the cyber assessment and documented disruption. Ransomware, threat-actor attribution and data theft remain low-confidence possibilities based on the stable Anubis claim, not confirmed incident facts. The public record does not establish whether the operational outage was caused by encryption, containment measures or another mechanism.

Analytic gaps

The public record does not identify the initial-access vector, exploited vulnerability, compromised identity or host, malware execution, encryption scope, attacker persistence, confirmed exfiltration, affected data types or people, ransom amount, negotiation, payment, final forensic findings or law-enforcement conclusions.

Threat actor and claim

Listed as: Signature HealthcareSource: otherPublished: Discovered:

Claim details

Anubis claimed responsibility, alleged theft of 2 TB of patient data and imposed a seven-day payment deadline. Signature Healthcare did not confirm the actor, encryption, data theft, demand amount or payment; the claim remains low confidence.

Organizations involved

Impacted locations

  • Bridgewater, Massachusetts

    Medium Confidence

    Signature Medical Group practice in Bridgewater. Signature said health-system information systems were affected and practices remained open with delays, but it did not specify the exact disruption at this site.

  • Easton, Massachusetts

    Medium Confidence

    Signature Medical Group practice in North Easton, within the town of Easton. Signature said health-system information systems were affected and practices remained open with delays, but it did not specify the exact disruption at this site.

  • Raynham, Massachusetts

    Medium Confidence

    Signature Medical Group practice in Raynham. Signature said health-system information systems were affected and practices remained open with delays, but it did not specify the exact disruption at this site.

  • Stoughton, Massachusetts

    Medium Confidence

    Signature Medical Group and urgent-care operations in Stoughton. Signature said health-system information systems were affected and practices remained open with delays, but it did not specify the exact disruption at this site.

Sources

Signature Healthcare hit by cyber incident in Massachusetts

DysruptionHub reported that Signature Healthcare shifted Brockton Hospital to downtime procedures after suspicious network activity. Ambulances were diverted, staff documented care on paper, chemotherapy infusions were canceled and pharmacies in Brockton and East Bridgewater were closed or limited, while inpatient and walk-in emergency care remained open and scheduled procedures continued.

Alert Announcements

Signature Healthcare said it detected suspicious activity, activated incident response and moved to downtime procedures on April 6. Its updates documented ambulance diversion, chemotherapy cancellation, patient-portal and medical-record unavailability, delayed testing and pharmacy limits; it lifted Code Black April 15 and said April 24 that pharmacies were open as it completed a return to full operations.

Cybercriminals give Brockton, MA hospital one week to pay ransom after hack

Comparitech reported that Anubis listed Signature Healthcare on its data-leak site, claimed 2 TB of sensitive patient data and gave the victim seven days to pay before release. The report said Signature Healthcare had not acknowledged the claim and that the data volume, demand, payment status and intrusion method were not independently verified.

Signature Healthcare - Ransomware victim

SOCRadar’s ransomware intelligence record identifies Signature Healthcare as a claimed Anubis victim discovered April 9, 2026, in the United States healthcare sector. The tracker labels the victim status as claimed rather than independently confirmed.

Cyberattack continues to disrupt operations at Signature Healthcare

TechTarget reported continuing recovery on April 15, including paper-based work while electronic health-record systems remained down. It summarized Signature’s April 10 notice that ambulance traffic was diverted, the patient portal and medical-record requests were unavailable, lab work could be delayed and pharmacies could not fill prescriptions, and separately reported the unconfirmed Anubis claim.

Services at Brockton hospital return to normal more than a week after cyberattack

Boston.com reported that Brockton Hospital resumed receiving ambulances after lifting Code Black on April 15. Signature Healthcare described this as a major recovery milestone but said some systems and processes remained offline for restoration over the following days while forensic work continued.

Signature Healthcare

Official profile information supporting the public description of Signature Healthcare Corporation.

Geographic profiles for selected U.S. locations

Official geographic reference used with local and state material to verify place names, jurisdiction types and location context for plymouth, plymouth, bridgewater, brockton, easton, stoughton, raynham, bristol.

See something that needs correction?

Signed-in members can report an error, update, or missing source.