Security News

Cybersecurity news aggregator

💀
HIGH Attacks SecurityWeek

1.2 Million Affected by University of Hawaii Cancer Center Data Breach

A ransomware attack on August 31, 2025, encrypted servers at the University of Hawaiʻi Cancer Center, impacting research data. The threat actors' extensive encryption hindered system restoration and data assessment. The university engaged with the attackers, obtained a decryption tool, and is providing credit monitoring to the 1.2 million affected individuals.
Read Full Article →

Data Breaches 1.2 Million Affected by University of Hawaii Cancer Center Data Breach Hackers stole names, Social Security numbers, driver’s license information, voter registration records, and health-related information. By Ionut Arghire | March 3, 2026 (8:34 AM ET) Flipboard Reddit Whatsapp Whatsapp Email The personal information of approximately 1.2 million people was compromised in a ransomware attack at the University of Hawaiʻi Cancer Center. The incident occurred on August 31, 2025, and affected servers supporting the center’s research operations, with no impact on clinical operations or patient care. According to an incident notice the University of Hawaiʻi published last week, “the extensiveness of the encryption by the threat actors” made it difficult to restore the affected systems and assess the compromised data. The university says it engaged with the threat actors “to protect the individuals whose sensitive information may have been compromised,” and that it obtained a decryption tool and ensured the destruction of exfiltrated data. The institution did not share details on the paid ransom. Most of the compromised data, the university says, was associated with a study established in 1993, as part of which more than 215,000 people were recruited between 1993 and 1996. The records of 87,493 study participants were compromised in the attack. These records include names, Social Security numbers, and, for some participants, research-related and health information was also impacted. Advertisement. Scroll to continue reading. Additionally, the names, driver’s license details, Social Security numbers, and voter registration records of approximately 1.15 million people were compromised, the university says. “There was no impact to information held by the UH Cancer Center’s Clinical Trials operations, patient care, or any other divisions of the UH Cancer Center. There was no impact on UH student records,” the institution says. University of Hawaiʻi is providing the impacted individuals with 12 months of free credit monitoring and identity theft services. The university says its investigation into other potentially compromised information continues, with support from law enforcement and cybersecurity experts. Related: Madison Square Garden Data Breach Confirmed Months After Hacker Attack Related: Canadian Tire Data Breach Impacts 38 Million Accounts Related: 38 Million Allegedly Impacted by ManoMano Data Breach Related: CarGurus Data Breach Impacts Over 12 Million Users Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. More from Ionut Arghire North Korean APT Targets Air-Gapped Systems in Recent Campaign Google Working Towards Quantum-Safe Chrome HTTPS Certificates Hackers Weaponize Claude Code in Mexican Government Cyberattack Canadian Tire Data Breach Impacts 38 Million Accounts 38 Million Allegedly Impacted by ManoMano Data Breach 900 Sangoma FreePBX Instances Infected With Web Shells Aeternum Botnet Loader Employs Polygon Blockchain C&C to Boost Resilience Gambit Security Emerges From Stealth With $61 Million in Funding Latest News New ‘AirSnitch’ Attack Shows Wi-Fi Client Isolation Could be a False Sense of Security Android Update Patches Exploited Qualcomm Zero-Day Iran Cyber Front: Hacktivist Activity Rises, but State-Sponsored Attacks Stay Low Vulnerability in MS-Agent AI Framework Can Allow Full System Compromise Researchers Uncover Method to Track Cars via Tire Sensors Vulnerability Allowed Hijacking Chrome’s Gemini Live AI Assistant OpenClaw Vulnerability Allowed Websites to Hijack AI Agents Madison Square Garden Data Breach Confirmed Months After Hacker Attack Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Identity Under Attack: Why Every Business Must Respond Now February 11, 2026 Attendees will walk away with guidance for how to build robust identity defenses, unify them under a consistent security model, and ensure business operations move quickly without compromise. Register Virtual Event: Ransomware Resilience & Recovery 2026 Summit February 25, 2026 SecurityWeek’s 2026 Ransomware Summit will discuss a roadmap for defending the enterprise, from mitigating root causes to mastering recovery, giving security teams the critical insights needed to navigate and neutralize today’s ransomware extortion threats. Submit People on the Move Nick Andersen has been appointed Acting Director of CISA after the departure of Madhu Gottumukkala. Predictive revenue system company Clari + Salesloft has named Peter Liebert as CISO. Nscale has appointed Latha Maripuri as Chief Information Security Officer. More People On The Move Expert Insights Four Risks Boards Cannot Treat as Background Noise The goal isn’t about preventing every attack but about keeping the business running when attacks succeed. (Steve Durbin) How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable. (Matias Madou) Security in the Dark: Recognizing the Signs of Hidden Information Security failures don’t always start with attackers, sometimes they start with missing truth. (Joshua Goldfarb) Living off the AI: The Next Evolution of Attacker Tradecraft Living off the AI isn’t a hypothetical but a natural continuation of the tradecraft we’ve all been defending against, now mapped onto assistants, agents, and MCP. (Etay Maor) Why We Can’t Let AI Take the Wheel of Cyber Defense The fastest way to squander the promise of AI is to mistake automation for assurance, and novelty for resilience. (Steve Durbin) Flipboard Reddit Whatsapp Whatsapp Email

Share this article