Nacogdoches Memorial Hospital, an independent health system in Texas, disclosed a cyberattack that exposed sensitive information belonging to 257,073 individuals. The hospital said staff identified an ongoing intrusion on January 31, while a filing to Maine indicated the incident date was January 15, creating some uncertainty around the precise timeline of the breach.
The compromised data may include names, contact information, Social Security numbers, dates of birth, medical record numbers, account numbers, health plan beneficiary numbers, and in some cases full-face photographs. Reporting indicated the incident had not yet appeared on the U.S. Department of Health and Human Services public breach portal at the time of disclosure, and it remained unclear whether the total affected population included only patients or also employees.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Nacogdoches Memorial Hospital publicly disclosed a data breach affecting 257,073 individuals. Reporting said the total may include patients and possibly employees, though the incident had not yet appeared on the U.S. Department of Health and Human Services public breach tool at the time of coverage.
Nacogdoches Memorial Hospital said staff became aware of an ongoing cyberattack on 2026-01-31. The discovery indicated the attack was active at that time and prompted the hospital's response.
A notification filed with Maine indicates the data breach incident at Nacogdoches Memorial Hospital occurred on 2026-01-15. The exposure potentially involved names, contact details, Social Security numbers, dates of birth, medical record numbers, account numbers, health plan beneficiary numbers, and possibly full-face photographs.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.