Claim details
Medusa claimed UMMC, demanded $800,000 and posted sample images; UMMC did not confirm attribution or the alleged theft.
A ransomware attack struck the University of Mississippi Medical Center on Feb. 19, 2026, disabling Epic records, phone and email systems and closing 35 clinics across 23 Mississippi municipalities. Clinics and phone service returned March 2 after nine days, while Medusa later claimed the attack and demanded $800,000 to prevent publication of allegedly stolen data.
The organization publicly identifies the event as cyber-related. The organization publicly documents the resulting service disruption.
Malware that encrypts systems or data, typically accompanied by a ransom demand.
Data was copied, transferred, downloaded, or otherwise removed from the affected environment by an unauthorized party.
Stolen, exposed, or otherwise compromised data was publicly released, posted, distributed, or offered for download.
Data was rendered inaccessible through unauthorized encryption, including ransomware-related encryption.
Authorized users could not access required data because of the incident, even when the data was not encrypted, deleted, or destroyed.
A primary service, system, platform, or operational capability became entirely unavailable.
Email sending, receiving, access, or related messaging functions were unavailable or materially impaired.
Telephone, voice-over-IP, call-center, or related voice communication services were unavailable or materially impaired.
A public-facing website was unavailable, disabled, or inaccessible.
Internal business, administrative, operational, or staff-facing systems were unavailable.
Clinical, diagnostic, pharmacy, patient-care, medical-record, or other healthcare operations were materially affected.
One or more offices, schools, clinics, stores, plants, branches, or other facilities closed because of the incident.
Scheduled events, meetings, hearings, classes, procedures, programs, or other activities were canceled.
Staff or users had to rely on paper, telephone, in-person, offline, or other manual processes.
Employees were sent home, placed on administrative leave, furloughed, or otherwise removed from normal duties because of the incident.
Customers, residents, patients, students, vendors, or members of the public faced access restrictions or could not use services normally.
The victim received a demand for payment in exchange for restoring access, decrypting systems, preventing disclosure, or stopping another threatened action.
The extortion activity involved unauthorized encryption of systems or data, with restoration or decryption conditioned on payment.
The actor threatened to disclose, sell, distribute, or otherwise misuse stolen data unless the victim paid or complied with demands.
The actor explicitly threatened to publish or publicly release victim data or incident details.
The victim was listed on a threat actor or ransomware data-leak site as an alleged target or nonpaying victim.
The actor published or shared a sample of allegedly stolen victim data to substantiate the extortion claim.
The actor imposed a deadline or public countdown before increasing the demand, publishing data, deleting keys, or taking another threatened action.
The actor directly contacted the victim through a ransom note, email, chat portal, telephone call, messaging platform, or other communication channel.
DysruptionHub assesses with high confidence that the University of Mississippi Medical Center experienced a ransomware attack beginning Feb. 19, 2026. UMMC called the event a cybersecurity attack in its first public statement and later confirmed that intruders demanded financial compensation to decrypt affected systems. Our initial Feb. 19 reporting documented widespread system outages, statewide clinic closures and canceled outpatient care.
Medusa claimed responsibility March 12, demanded $800,000 and posted images it described as samples of stolen UMMC documents. UMMC has not confirmed Medusa’s role or that data was stolen, so the actor relationship remains a medium-confidence claim rather than confirmed attribution.
UMMC later said its monitoring detected irregular activity in the early hours of Feb. 19 as users began reporting problems. The organization shut down affected systems to contain the threat. UMMC said the incident was not caused by a single user error or someone clicking a malicious email, but it has not disclosed the initial-access mechanism.
The attack cut off access to Epic electronic health records and disrupted phone, email, Wi-Fi, website and other internal systems. UMMC closed all 35 clinics statewide, canceled outpatient and ambulatory surgeries and procedures, canceled imaging appointments, sent some staff home and used paper-based downtime procedures. The Jackson Medical Mall dialysis clinic continued scheduled care. Hospitals and emergency departments remained open, including facilities in Jackson, Grenada, Canton and Lexington, but UMMC temporarily diverted some transfers before resuming higher-level-care transfers Feb. 20. Staff made special arrangements for time-sensitive treatments, and chemotherapy restarted Feb. 23.
The disruption also affected organizations that depended on UMMC systems. Mississippi county health departments used paper charts while their UMMC electronic-record dependency was unavailable, although those departments remained open. UMMC later said all mission areas were affected and patient care was hit hardest. February revenue finished about 20% below budget, and the outage briefly delayed the Medical Center’s budget process.
UMMC said all of its locations were affected. Its July 2025 statewide-presence map and facility directory support incident locations in 23 municipalities: Batesville, Bay St. Louis, Biloxi, Canton, Ecru, Flowood, Grenada, Gulfport, Hattiesburg, Iuka, Jackson, Lexington, Louisville, Madison, McComb, Meridian, Oxford, Ridgeland, Tupelo, Vaiden, Vicksburg, West and Winona. Multiple hospitals or clinics in the same municipality are represented by one deduplicated geographic record.
UMMC said the attackers communicated directly and demanded payment in exchange for decrypting affected systems, independently confirming ransomware without relying on the later Medusa claim. Medusa’s listing added an alleged data-theft component, sample publication, a public leak threat and a deadline. Those actions establish extortion indicators but do not prove Medusa caused the intrusion or that its descriptions of the data were accurate.
As of UMMC’s April 27 public response, forensic work was still examining what data may have been accessed or exfiltrated. UMMC had not confirmed patient-data theft, Medusa attribution or whether any payment was made.
Confidence is high that ransomware caused the disruption because UMMC described a payment demand for decryption and documented the resulting system outages. Confidence is also high in the organizationwide operational scope. Medusa attribution and alleged data theft remain medium-confidence claims because UMMC has not corroborated them.
UMMC said it was largely back to normal by Feb. 28. Clinics resumed normal operations and phone service returned March 2, with staff beginning to reschedule canceled appointments. Most systems used in regular operations were back online by March 13. The service-delivery disruption is resolved; the continuing forensic investigation does not make the incident operationally active.
The public record does not establish initial access, the precise ransomware variant, the full set of encrypted systems, the amount or categories of data allegedly stolen, whether a payment was made, Medusa’s actual role or the final notification population.
Medusa claimed UMMC, demanded $800,000 and posted sample images; UMMC did not confirm attribution or the alleged theft.

UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Batesville. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Bay St. Louis. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Biloxi. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Canton. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Ecru. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Flowood. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Grenada. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Gulfport. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Hattiesburg. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Iuka. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Lexington. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Louisville. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Madison. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in McComb. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Meridian. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Oxford. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Ridgeland. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Tupelo. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Vaiden. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Vicksburg. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in West. UMMC said all locations were affected and all statewide clinics closed.
UMMC's preincident presence map and facility directory identify one or more hospitals or clinics in Winona. UMMC said all locations were affected and all statewide clinics closed.
We reported Feb. 19 that UMMC said a cybersecurity attack disabled Epic and other IT systems, closed all clinic locations statewide and canceled outpatient procedures, ambulatory care and imaging appointments.
UMMC’s July 2025 statewide-presence map identifies preincident hospitals or clinics in Batesville, Bay St. Louis, Biloxi, Canton, Ecru, Flowood, Grenada, Gulfport, Hattiesburg, Iuka, Jackson, Lexington, Louisville, Madison, McComb, Meridian, Oxford, Ridgeland, Tupelo, Vaiden, Vicksburg, West and Winona.
WLBT reported that UMMC shut down IT systems, lost access to electronic medical records, closed all 35 clinics and said attackers had communicated with the institution.
Mississippi Today reported that LouAnn Woodward said all UMMC locations were affected. All clinics closed, most elective care was canceled, hospitals used paper procedures, and county health departments that relied on UMMC records also shifted to paper charts while remaining open.
UMMC said phone and email remained unavailable or unreliable, federal teams and outside vendors were assisting, hospitals and emergency departments continued operating and transfers resumed.
UMMC leadership said threat actors sought financial compensation in exchange for decrypting the medical center’s electronic platform and other affected systems and had left demands.
Mississippi Today reported that statewide clinics would resume normal operations and scheduled appointments March 2 after being closed for more than a week.
UMMC said clinics resumed normal operations March 2 after a nine-day cyberattack. All mission areas were affected, patient care was hit hardest, staff used paper workflows, chemotherapy restarted Feb. 23, and hospitals and emergency departments stayed open.
Comparitech reported that Medusa claimed the attack, demanded $800,000 within one week and posted sample images of documents it alleged were stolen from UMMC.
UMMC said monitoring detected irregular activity early Feb. 19 as users reported problems, prompting containment shutdowns. It said the attack was not caused by one user clicking a malicious email, operations were largely normal by Feb. 28, and data-access analysis continued.
Mississippi Today reported that UMMC was still determining what data was accessed or exfiltrated, had not confirmed Medusa or a ransom payment, and finished February about 20% below its revenue budget after the nine-day disruption.
UMMC’s public directory identifies its hospitals and clinics by address. Cross-checked against UMMC’s July 2025 presence map, it supports 23 incident-era facility municipalities while allowing multiple facilities in one municipality to be deduplicated.
Signed-in members can report an error, update, or missing source.