Madera Community Hospital disclosed a data breach affecting 150,810 individuals after an unauthorized party accessed its internal network for two days in late May 2025 and likely acquired files from part of the environment. The California hospital said the exposed information included names, contact details, dates of birth, Social Security numbers, login credentials, financial account information, treatment and health insurance data, and limited biometric information.
The hospital detected the intrusion on May 29, 2025, initially found no evidence of file theft during its early investigation, and later concluded that data had likely been exfiltrated. It said an extortion group was behind the incident and had issued a ransom demand before reportedly withdrawing it after learning the victim was a hospital and saying it did not want to harm patients. Madera Community Hospital said it secured the affected network, hired third-party cybersecurity and data-review firms, notified law enforcement and the US Department of Health and Human Services, and began notifying affected individuals in mid-July 2026 after receiving data-review results in April 2026.

See attribution, scope, and your downstream exposure.
5 events from the most recent confirmed update back to the earliest known activity.
Madera Community Hospital began notifying potentially impacted individuals in mid-July 2026. The hospital ultimately reported to the U.S. Department of Health and Human Services that 150,810 people were affected.
Madera Community Hospital said it received the results of its data review in April 2026. After that, it worked to ensure accurate contact information for potentially impacted individuals.
A forensic investigation in June 2025 determined that an unauthorized third party had access to the hospital's computer network for two days in late May 2025. The initial investigation did not identify any files as having been taken.
Madera Community Hospital identified unauthorized access to its internal network on May 29, 2025. It launched an investigation, secured the affected network, engaged external cybersecurity experts, and notified law enforcement.
Subsequent developments led Madera Community Hospital to believe that files from part of its network were acquired by the intruder. The hospital identified potentially exfiltrated files and said the compromised data included personal, financial, medical, insurance, credential, and limited biometric information.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.