The University of Mississippi Medical Center (UMMC) reported a ransomware attack that knocked multiple IT systems offline, including access to its Epic electronic health record (EHR) platform, triggering the organization’s emergency operations plan. The disruption forced UMMC to close all 35 clinics statewide and cancel outpatient, elective, and clinic procedures, while hospital and emergency services remained open under contingency operations.
UMMC stated the attackers have been in communication and that it is working with external specialists and law enforcement; the FBI is investigating and warned the duration of the outage was unknown at the time of reporting. Separate reporting also described a different municipal incident in Meriden, Connecticut, where officials took city internet services and public Wi‑Fi offline after an attempted disruption; emergency services were reported as unaffected and the city said it would conduct a comprehensive review before restoring service.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-20, UMMC said clinic closures and canceled elective services were continuing for a second consecutive day while officials assessed the incident and worked to restore offline systems. The organization warned the disruption could last for days, although hospital and emergency care remained operational.
By 2026-02-19, UMMC leadership said the attackers had communicated with the organization, though it did not identify the group or disclose any ransom demands. No ransomware gang had publicly claimed responsibility at that time.
On 2026-02-19, UMMC said it was working with law enforcement and federal agencies including the FBI, CISA, and DHS, along with outside specialists, to investigate and respond to the ransomware incident. Officials said it was too early to determine the full impact, including whether patient data was compromised or how long recovery would take.
Following the attack on 2026-02-19, UMMC closed all or most clinic locations across Mississippi and canceled elective procedures, outpatient and ambulatory surgeries, imaging appointments, and other non-emergency services. Hospitals and emergency rooms remained open using downtime procedures, with staff in some areas reverting to paper documentation.
On 2026-02-19, the University of Mississippi Medical Center detected a ransomware attack that compromised or disrupted multiple IT systems, including access to its Epic electronic medical records platform. UMMC took network systems offline as a precaution and activated its emergency operations plan.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcetechxplore.com
Open sourcebleepingcomputer.com
Open sourceteiss.co.uk
Open sourcedatabreaches.net
Open sourcegovinfosecurity.com
Open sourcebankinfosecurity.com
Open sourcewlbt.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.