2026 Signature Healthcare (MA) — Anubis ransomware; ~2TB data theft claimed; clinical disruption
Data compromised
Patient and operational health data alleged—scope subject to official breach letters
Technical writeup
Signature Healthcare, a Massachusetts community health system, was the subject of intensive April 2026 trade reporting after the Anubis ransomware-as-a-service operation listed the organization and claimed theft of on the order of two terabytes of patient information while stating it had not encrypted systems in the same operation—claims that could not be fully independently verified at article time. News outlets described significant care disruption, including diversion of some emergency traffic and reliance on manual workflows while EHR and patient portal systems were unavailable, with recovery timelines discussed in weeks. The victim entry later disappeared from the actor leak site amid evolving extortion dynamics. Organizations should rely on Signature Healthcare’s own patient notifications for confirmed data categories and populations.
Root cause
Ransomware / data-extortion operation (Anubis claimed; technical details per hospital and law enforcement)