Mile Bluff Medical Center in Mauston, Wisconsin disclosed a security incident involving data encryption that disrupted some phone and computer functions across the organization. The hospital said it immediately activated security protocols, began an investigation with internal specialists and third-party partners, and moved clinical teams to downtime procedures to preserve continuity of care while systems were affected.
Hospital leadership said the disruption was limited, temporary, and narrow in scope, and that patient safety was maintained during the response. Public reporting indicated no criminal group had claimed responsibility at the time of disclosure, while Mile Bluff's public statement and follow-on reporting framed the event as a contained cyber incident that affected operational technology and communications rather than halting care delivery.

See the actors and campaigns active against you right now.
3 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting said there had been no additional public update from Mile Bluff Medical Center and no criminal group had publicly claimed responsibility for the incident at that time.
Mile Bluff publicly stated that clinical teams had shifted to downtime procedures to maintain continuity of care and that patient safety was maintained. CEO Dara Bartels said the impact was limited, temporary, and narrow in scope.
Mile Bluff Medical Center disclosed that it experienced a security incident involving data encryption that disrupted some phone and computer system functions. The organization said it immediately activated security protocols and began investigating with internal experts and third-party partners.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.