Nacogdoches Memorial Hospital in Texas disclosed that a January cyberattack exposed the personal and medical information of 257,073 patients after attackers gained access to its network on January 15 and remained undetected for roughly two weeks. Public reporting and breach notification materials indicate the stolen data included names, Social Security numbers, medical record numbers, health insurance and health plan beneficiary details, and other sensitive healthcare information; the hospital also said patient photos may have been affected.
The regional medical center said it has not identified misuse of the stolen data so far, but the scale and sensitivity of the breach make it a significant healthcare privacy incident. In response, the hospital said it implemented additional network security measures and security awareness training, while reports noted it did not offer complimentary credit monitoring to affected individuals and did not provide further detail on the intrusion or whether employee and support staff data was also compromised.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
Following the incident, Nacogdoches Memorial Hospital said it added network security improvements and security awareness training. The hospital did not offer complimentary credit monitoring to affected individuals.
The hospital disclosed that 257,073 patients had personal and medical information stolen, including Social Security numbers, medical record numbers, health plan beneficiary numbers, and possibly patient photos. It said there was no indication of misuse at the time of disclosure.
The hospital discovered the breach roughly two weeks after the initial compromise. The incident was found in late January 2026 after attackers had already accessed sensitive data.
Nacogdoches Memorial Hospital said threat actors gained access to its network on January 15, 2026. The intrusion led to unauthorized access to patient personal and medical information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.