OneBlood, a non-profit organization supplying blood to 250 hospitals across four states, experienced a significant ransomware attack in July 2024. The cybercriminals gained unauthorized access to OneBlood's computer network between July 14 and July 29, 2024. As a result of this breach, the personal information of approximately 167,400 individuals was compromised or potentially exposed. The compromised data included names, Social Security numbers, payment card information, and sensitive medical data. Following the incident, OneBlood faced a proposed class action lawsuit from affected individuals. To resolve the litigation, OneBlood agreed to a $1 million settlement, which was preliminarily approved by a Broward County, Florida circuit court. Under the terms of the settlement, affected individuals are eligible to claim up to $2,500 for documented losses or opt for a $60 cash payment. A final court hearing regarding the settlement is scheduled for December 9. OneBlood has denied any wrongdoing in connection with the incident. The attack on OneBlood was part of a broader trend, as several other blood suppliers in the US and UK also suffered cyber incidents during the same period. The breach highlighted the vulnerability of healthcare and critical infrastructure organizations to ransomware attacks. The incident prompted OneBlood to notify all affected donors and individuals whose data may have been compromised. The organization undertook an internal investigation to determine the scope and impact of the breach. The settlement aims to provide financial relief to those impacted by the exposure of their sensitive information. The case underscores the increasing financial and reputational risks faced by healthcare providers in the wake of cyberattacks. The attack and subsequent settlement have drawn attention to the need for enhanced cybersecurity measures in the healthcare sector. The incident also serves as a warning to other organizations handling sensitive personal and medical data. Regulatory scrutiny and litigation risks are likely to increase for organizations that experience similar breaches. The OneBlood case demonstrates the potential costs and consequences of ransomware attacks on critical service providers.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
OneBlood agreed to pay a $1 million settlement related to a ransomware incident, according to reports published on September 29, 2025. The available references do not provide additional details about the underlying attack date, impact, or settlement terms.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.