TL;DR:
- Brockton Hospital detected a cyberattack on April 6, 2026. The emergency room diverted ambulances. Chemotherapy infusion treatments for cancer patients were canceled. Pharmacies closed. The electronic medical records system went dark.
- The Anubis ransomware gang claimed responsibility on April 9, saying they stole 2 terabytes of "critical" and "sensitive" patient information. They say they didn't encrypt systems, just took the data.
- By April 11, Signature Healthcare disappeared from Anubis's leak site. A spokeswoman declined to say whether the hospital is negotiating or paying a ransom.
- Staff switched to pen and paper. The 125-year-old community hospital expects a full two-week recovery timeline to bring systems back online.
- Anubis has hit 70+ victims since February 2025, with healthcare as a primary target. The group has a built-in wiper that can permanently destroy files, even after payment.
What Happened at Brockton Hospital
On the morning of April 6, 2026, Signature Healthcare's IT team detected suspicious activity on a portion of their network at Brockton Hospital in Massachusetts. They activated incident response protocols. By Monday April 7, the damage was clear: the electronic medical records system was down, internet service was gone, and the hospital had no choice but to divert ambulances to other facilities [1].
Here's what went offline:
- Emergency department: Placed on ambulance diversion. Walk-in patients could still be seen, but emergency medical crews were rerouted to other hospitals.
- Chemotherapy: Cancer patients scheduled for Tuesday April 7 infusions were told their treatments were canceled. Some chemo resumed by April 8 for existing patients only.
- Pharmacies: The retail pharmacies in Brockton and East Bridgewater shut down. Staff could consult with patients but couldn't fill prescriptions.
- Lab services: Diagnostic testing and laboratory work experienced delays.
- Medical records: Patient portal offline. Medical records requests frozen. Staff reverted to pen-and-paper documentation for all patient interactions.
Scheduled surgeries and procedures continued. Doctors still had their hands and their training. But everything that depended on a computer screen stopped working [2].
"Upon identifying suspicious activity within a portion of our network, we immediately activated our incident response protocols," a hospital spokesperson said. They contacted law enforcement and brought in external cybersecurity experts. They declined to confirm whether the incident was ransomware [3].
Two days later, someone else confirmed it for them.
Anubis: "We Have 2 Terabytes"
On April 9, the Anubis ransomware operation posted Signature Healthcare on its dark web leak site. Their claim: 2 terabytes of "critical" and "sensitive" patient information stolen from the hospital's systems [4].
Anubis said they did not encrypt the hospital's systems. This is a deliberate strategy, data theft without encryption means the hospital can technically keep operating (on degraded systems), but the extortion threat remains: pay up, or we publish everything.
Then something unusual happened. By Friday morning, April 11, Signature Healthcare's listing vanished from Anubis's leak site. A spokeswoman for the hospital declined to say whether the organization was negotiating with or paying the attackers [5].
When ransomware groups remove a victim from their public shaming page, it usually means one of two things: payment is in progress, or negotiations have started. Neither option is great for the patients whose medical records may be in the hands of criminals.
Who Is Anubis?
Anubis operates as a Ransomware-as-a-Service (RaaS) platform. It first surfaced in December 2024 as a prototype called "Sphinx," then rebranded and went operational in February 2025. The operators communicate in Russian on dark web forums and run an affiliate program with negotiable revenue splits [6].
Since February 2025, Anubis has claimed at least 70 victims across multiple countries including the United States, France, Australia, and Peru. Healthcare is a favorite target. Their very first known victim was a medical centre in Victoria, Australia, back in November 2024. A Canadian healthcare organization followed in December 2024 [7].
What makes Anubis particularly dangerous: the software includes an optional wiper mode. It doesn't just encrypt files, it can permanently erase them. Security researchers at Trend Micro documented cases where victims lost their data forever, even after paying the ransom [8].
The group also runs a regulatory pressure playbook. They threaten to report breaches to the UK's ICO, the US Department of Health and Human Services, the European Data Protection Board, and other regulatory bodies, adding legal pressure on top of the data theft pressure. It's extortion with a compliance twist [9].
Healthcare's Ransomware Epidemic
Brockton Hospital isn't an isolated case. It's one entry in a spreadsheet that keeps getting longer.
Analysis of HHS Office for Civil Rights breach filings shows 301,768,951 individuals affected across 735 healthcare breach filings. Change Healthcare alone accounts for 192.7 million. Strip that out and you've still got 109 million+ people whose medical records were compromised [10].
Six new healthcare breaches were announced in the week before the Signature Healthcare attack, including CareCloud (45,000+ providers, 8-hour unauthorized access to EHR systems) and Conduent (25 million+ Americans affected). Ransomware groups have figured out what every hospital administrator already knows: healthcare systems are underfunded, understaffed on IT, running legacy software, and absolutely cannot afford downtime [11].
When a factory gets ransomware'd, production stops. When a hospital gets ransomware'd, cancer patients don't get chemotherapy. Ambulances drive past the nearest ER. Doctors write prescriptions on paper that pharmacies can't fill.
The incentive to pay is enormous. And the attackers know it.
Two Weeks on Paper
Signature Healthcare expects it will take approximately two weeks to fully restore systems. That's two weeks of a 125-year-old community hospital operating without electronic records. Two weeks of handwritten notes, verbal orders double-checked by hand, and delayed lab results [12].
For context: Brockton Hospital serves a community of roughly 100,000 people south of Boston. It's not a major research hospital with unlimited IT budgets. It's a community health system, the kind of facility that people in the area depend on because it's the closest hospital they've got.
The hospital says it has notified law enforcement and engaged third-party cybersecurity specialists. No word yet on whether the 2TB of allegedly stolen data includes patient Social Security numbers, insurance information, medical diagnoses, or prescription records, all of which would be standard contents of a healthcare system's databases.
If You're a Signature Healthcare Patient
Signature Healthcare hasn't confirmed what data was taken. But if you've been a patient at Brockton Hospital or any Signature Healthcare facility, here's what to do now:
- Freeze your credit at all three bureaus (Equifax, Experian, TransUnion). It's free. Do it today.
- Monitor your health insurance statements. Watch for claims you didn't make, medical identity theft is harder to detect and harder to fix than financial fraud.
- Don't trust calls or emails about the breach. Scammers will impersonate the hospital or "credit monitoring services." Any legitimate notification will come by postal mail.
- Check HaveIBeenPwned.com and set up alerts for your email addresses.
- Request your medical records once systems are back online and verify nothing was altered. Ransomware groups have been known to modify records, not just steal them.
The Bottom Line
A ransomware gang that communicates in Russian and runs an affiliate program just shut down a Massachusetts community hospital. Cancer patients lost their scheduled chemotherapy. Ambulances got sent somewhere else. Pharmacies closed. And 2 terabytes of medical records may now sit on a server controlled by criminals who have a documented history of destroying data even when victims pay.
Brockton Hospital's staff went back to paper charts, the same way they did things when the hospital was founded in 1901. Except now the stakes include whether the most intimate details of 100,000 patients' medical histories end up for sale on the dark web.
Two weeks. That's how long before the lights come back on. And that's assuming nothing else goes wrong.
Sources
- EMS1, "Brockton Hospital cyberattack diverts ambulances"
- The Cyber Express, "Signature Healthcare Cyberattack Disrupts Brockton Hospital"
- Boston Globe, "Brockton Hospital forced to use paper records after cyber incident"
- GovInfoSecurity, "RaaS Gang Anubis Claims Signature Healthcare Data Theft"
- DataBreaches.net, "Brockton Hospital still dealing with aftermath of ransomware attack"
- BitSight, "Anubis: A Deep Dive into the Emerging Ransomware"
- Ransomware.live, Anubis Group Profile
- Trend Micro, "Anubis: A Closer Look at an Emerging Ransomware"
- Proven Data, "Anubis Ransomware: Operational Profile, Attack Chain, and Response Priorities"
- HIPAA Journal, "Ambulances Diverted from Brockton Hospital"
- SecurityWeek, "Massachusetts Hospital Diverts Ambulances as Cyberattack Causes Disruption"
- NBC Boston, "Brockton Hospital cyberattack aftermath continues"