Just how many cyberattacks are there in the Midwest? We compiled a list.

Search, filter, and sort attacks known near your location

Known or suspected cyber attacks in the last five years, ending March 31, 2026.

In the last five years, starting March 31, 2021 through March 31, 2026, there were 43 confirmed cyberattacks in the Midwest. One attack was attempted and one other was suspected. If that seems low, it’s because it is. And in the time since we compiled this list and this publication, Iranian-linked hackers have claimed control of the St. Joseph County, Indiana (home of South Bend and Notre Dame University) infrastructure, records, and systems.

How we compiled data on cyberattacks

Looking at publicly-available data we compiled a list by looking at public press releases, news reports, public government reports, and, in some cases, public notices from the attackers.

  • We only sought information on large-scale industries, healthcare facilities, schools, and commercial operations.
  • Small businesses under 50 people and individuals are not included.
  • We only looked at information available in 12 Midwest states (IA, IL, IN, KS, MI, MN, MO, ND, NE, OH, SD, WI)
OrganizationSectorIncident DateAttack TypeImpact SummaryAttacker / GroupAttribution StatusAttributed Origin / NexusCity / TownStateNotes
NEW CooperativeAgriculture / food supply2021-09-20Ransomware / operational disruptionAgricultural cooperative suffered a ransomware event with supply-chain concerns.BlackMatterClaimed by attacker / reportedRussian-speaking / Russia-linkedFort DodgeIowaOften described in reporting as a Russia-linked or Russian-speaking ransomware operation.
Des Moines Public SchoolsEducation2023-01-09Ransomware / data theftDistrict took networked systems offline and later confirmed stolen data.Unnamed ransomware groupVictim confirmed ransomware but did not publicly name group in cited sourceUnknownDes MoinesIowaDistrict said it received but did not pay a ransom demand.
Clarke County HospitalHealthcare2023-04-14Ransomware / data breachHospital shut down network access and later disclosed exposure of patient data.RoyalClaimed by attacker / reportedUnknown / not publicly specified in cited sourceOsceolaIowaRoyal leak-site claim was reported after the attack.
City of Cedar FallsGovernment2024-06-19Ransomware / data breachMunicipal breach led to resident notifications and compromised SSNs.BlackSuitClaimed by attacker / reportedUnknown / not publicly specified in cited sourceCedar FallsIowaComparitech reported BlackSuit claimed the incident.
Ann & Robert H. Lurie Children's Hospital of ChicagoHealthcare2024-01-31Cyberattack / suspected ransomwareWeeks-long network outage affecting records, phones, and operations.RhysidaClaimed by attacker / hospital said known criminal threat actorUnknown / not publicly specified in cited sourceChicagoIllinoisHospital confirmed a known criminal threat actor; Rhysida was reported as the claiming group.
Community High School District 117Education2024-06-02Unauthorized access / data breachDistrict disclosed a June 2024 network intrusion affecting thousands.BlackSuitClaimed by attacker / not independently verifiedUnknown; group described in reporting as having Russian lineageLake VillaIllinoisComparitech cites district notice for unauthorized access between June 2 and June 12, 2024.
CDK GlobalTechnology / auto retail software2024-06-19Ransomware / service disruptionDealer management software outages disrupted thousands of auto dealerships.BlackSuitBelieved / reportedUnknown / not publicly specified in cited sourceHoffman EstatesIllinoisAttribution based on reporting and analyst statements; CDK did not publicly confirm the group in cited source.
Crystal Lake Elementary District 47Education2024-10-17Network disruption / data breachDistrict reported a network disruption and later notified victims of a data breach.RansomHubClaimed by attacker / not independently verifiedUnknown / not publicly specified in cited sourceCrystal LakeIllinoisIncident date reflects district notice date for the network disruption.
Logansport Community School CorporationEducation2021-04-01Ransomware / data theftSensitive student and staff information exposed after district attack.PysaClaimed by attacker / reportedUnknown / not publicly specified in cited sourceLogansportIndianaMonth approximate from public reporting.
Johnson Memorial HealthHealthcare2021-10-01RansomwareHospital operations disrupted; ambulance diversions; extended downtime and paper records.HivePublicly attributedUnknown / not publicly specified in cited sourceFranklinIndianaAttack described as beginning in October 2021.
Monroe County GovernmentGovernment2024-07-01Ransomware / network intrusionCounty services and systems were disrupted for about a week.BlackSuitPublicly attributedRussian Federation (per public reporting on group affiliation)BloomingtonIndianaCounty publicly tied outage to BlackSuit.
Clay County GovernmentGovernment2024-07-01RansomwareCounty issued a disaster declaration after servers were hit.LockBitClaimed by attacker / not independently verifiedUnknown / not publicly specified in cited sourceBrazilIndianaLockBit claim was reported after the county incident.
Indiana University HealthHealthcare2024-10-18Email compromise / data breachUnauthorized access to a team member email account exposed limited patient data.UnknownNot publicly attributedUnknownIndianapolisIndianaDate reflects initial detection date in official notice.
Kansas Judicial BranchGovernment / judiciary2023-10-12Ransomware / data theftCourt systems were disrupted in a major statewide judicial cyberattack.Affiliates of a Russian-based ransomware groupPublicly attributedRussian-basedTopekaKansasState officials publicly said affiliates of a Russian-based group were responsible.
Unified Government of Wyandotte County / Kansas City, Kansas Police DepartmentGovernment / public safety2024-05-01Cyberattack / service disruptionPolice and broader municipal services were disrupted by a network incident.BlackSuitClaimed by attacker / not independently verifiedUnknown / not publicly specified in cited sourceKansas CityKansasComparitech reported BlackSuit claimed the incident.
City of WichitaGovernment2024-05-05Ransomware / municipal service disruptionCity services were disrupted after a ransomware attack.LockBitClaimed by attacker / reportedUnknown / not publicly specified in cited sourceWichitaKansasLockBit claim reported after the Wichita incident.
McLaren Health CareHealthcare2023-08-01Ransomware / data theftLarge breach and operational disruption affected multiple McLaren facilities.ALPHV / BlackCatClaimed by attacker / reportedUnknown / not publicly specified in cited sourceGrand BlancMichiganMonth approximate; public reports tied the 2023 attack to ALPHV/BlackCat.
Grand Traverse County / City of Traverse CityGovernment2024-06-12RansomwareCounty and city government systems went offline after a ransomware incident.UnknownNot publicly attributedUnknownTraverse CityMichiganLocal reporting later identified the outage as a ransomware attack.
McLaren Health CareHealthcare2024-08-01Ransomware / data theftSecond major McLaren cyber incident in two years disrupted systems and exposed data.INC RansomClaimed by attacker / reportedUnknown / not publicly specified in cited sourceGrand BlancMichiganSeparate 2024 incident reported after the earlier 2023 McLaren event.
Wayne County GovernmentGovernment2024-10-01Cyberattack / service disruptionMajor county systems were affected in Michigan's largest county.UnknownNot publicly attributedUnknownDetroitMichiganMonth approximate from public reporting.
StrykerManufacturing / medical devices2026-03-11Cyberattack / destructive disruptionGlobal network disruption affected ordering, shipping, and manufacturing.HandalaClaimed by attacker / reportedIran-linkedPortageMichiganCompany said no malware or ransomware was involved; Handala publicly claimed the attack.
University of MinnesotaHigher education2021-07-21Unauthorized access / data breachUniversity disclosed unauthorized access affecting personal information.UnknownNot publicly attributedUnknownMinneapolisMinnesotaOfficial FAQ says access likely occurred in 2021; disclosure came later.
St. Paul Public SchoolsEducation2023-02-15Unauthorized access / data breachDistrict warned families after a data security incident affecting student information.UnknownNot publicly attributedUnknownSt. PaulMinnesotaDate approximate; suspicious activity was disclosed in 2023.
Minnesota Department of EducationGovernment / education2023-05-31File-transfer exploitation / data breachLarge student-data breach tied to a wider file-transfer software campaign.UnknownNot publicly attributed in cited sourceUnknownSt. PaulMinnesotaBreach was publicly linked to the wider MOVEit campaign, but no group is named in the cited source.
City of Saint PaulGovernment2025-07-25RansomwareMajor municipal digital security incident disrupted city systems and services.InterlockClaimed by attacker / reportedUnknown / not publicly specified in cited sourceSt. PaulMinnesotaOfficial city hub describes it as part of a growing wave of ransomware attacks; Interlock attribution came from external reporting.
Missouri Delta Medical CenterHealthcare2021-09-01Ransomware / data theftHospital reported ransomware incident and patient data exposure.HiveClaimed by attacker / reportedUnknown / not publicly specified in cited sourceSikestonMissouriMonth approximate from public reporting.
University of Central MissouriHigher education2024-02-07Attempted cyberattackUniversity took IT systems offline following an attempted attack on servers.UnknownNot publicly attributedUnknownWarrensburgMissouriUniversity described the event as an attempted cyberattack.
Jackson County GovernmentGovernment2024-04-02Suspected ransomware / service disruptionCounty offices closed and multiple public services were rendered inoperative.UnknownSuspected onlyUnknownKansas CityMissouriOfficials initially described the incident as potentially attributable to ransomware.
Pembina County Memorial HospitalHealthcare2023-04-13External system breach / data theftHospital disclosed an external system breach affecting employee and patient data.UnknownNot publicly attributedUnknownCavalierNorth DakotaHospital said an unauthorized party obtained access to its internal network.
Grand Forks Public SchoolsEducation2024-09-01Phishing / wire fraudDistrict lost about $2.2 million through a fraudulent ACH payment change.UnknownNot publicly attributedUnknownGrand ForksNorth DakotaMonth approximate from public reporting.
Dickinson Public SchoolsEducation2026-02-11Vendor impersonation / business email compromiseSophisticated email scam redirected nearly $5 million.UnknownNot publicly attributedUnknownDickinsonNorth DakotaPublic reporting described a sophisticated impersonation and invoice-fraud scheme.
Douglas County 911Government / public safety2022-10-04Ransomware / cryptovirusEmergency communications operations were affected by a cryptovirus.UnknownNot publicly attributedUnknownOmahaNebraskaThe incident affected public safety systems.
Nebraska Judicial BranchGovernment / judiciary2023-06-01Hack / unauthorized accessInternal intranet systems were hacked, but the judiciary said no data was lost.UnknownNot publicly attributedUnknownLincolnNebraskaMonth approximate from public reporting.
Winnebago Public SchoolsEducation2024-10-21Cyberattack / school outageSchool district cancelled classes after cyberattack shut down systems.InterlockClaimed by attacker / reportedUnknown / not publicly specified in cited sourceWinnebagoNebraskaInterlock claim was reported in later coverage.
Broken Bow Public SchoolsEducation2025-02-01Business email compromise / wire fraudDistrict lost more than $1 million in a phishing-driven scam.UnknownNot publicly attributedUnknownBroken BowNebraskaMonth approximate from public reporting.
Memorial Health SystemHealthcare2021-08-15RansomwareAmbulance diversions and cancellations followed a major hospital outage.HiveClaimed by attacker / reportedUnknown / not publicly specified in cited sourceMariettaOhioPublic reporting tied the August 2021 incident to Hive.
City of ClevelandGovernment2024-06-01RansomwareCity Hall and other systems were disrupted by a ransomware incident.UnknownNot publicly attributedUnknownClevelandOhioMonth approximate from public reporting.
City of ColumbusGovernment2024-07-18Ransomware / data breachCity breach led to notification of hundreds of thousands of residents.RhysidaClaimed by attacker; city separately said foreign cyber threat actorForeign actor (not publicly named by city)ColumbusOhioRhysida claim was reported; city used broader foreign-actor language.
Kettering HealthHealthcare2025-05-20Ransomware / data theftSystem-wide outage disrupted procedures, EHR access, phones, and scheduling.InterlockPublicly attributedUnknown / not publicly specified in cited sourceKetteringOhioKettering later said it had reason to believe Interlock launched the attack.
Brown County GovernmentGovernment2021-07-01Phishing / network shutdownA scam-link click shut down most of the county network for over a week.UnknownNot publicly attributedUnknownAberdeenSouth DakotaSummer 2021 incident; date approximate.
Black Hills Regional Eye InstituteHealthcare2025-01-08Hacking / data theft / ransomware claimUnauthorized party accessed and acquired patient information after a network incident.QilinClaimed by attacker / reportedUnknown / not publicly specified in cited sourceRapid CitySouth DakotaOfficial notice was posted on the organization's website on Aug. 29, 2025.
Group Health Cooperative of South Central WisconsinHealthcare2024-01-25Data theft / attempted encryptionMore than 500,000 records affected after a cyberattack and attempted encryption.BlackSuitClaimed by attacker / reportedForeign ransomware gangMadisonWisconsinReporting described the actor as a foreign ransomware gang; later reporting tied the claim to BlackSuit.
Waupaca County School DistrictEducation2024-05-01Cyberattack / possible ransomwareSchool district experienced a cyber incident later claimed by a ransomware gang.FogClaimed by attacker / not independently verifiedUnknown / not publicly specified in cited sourceWaupacaWisconsinMonth approximate from public reporting.
City of SheboyganGovernment2024-10-31Ransomware / data breachMunicipal systems disrupted; later breach notices indicated large resident impact.ChortClaimed by attacker / reportedUnknown / not publicly specified in cited sourceSheboyganWisconsinLater reporting associated the incident with Chort.
CellcomTelecommunications2025-05-14Cyberattack / service outageExtended outage affected voice and text services for Wisconsin customers.UnknownNot publicly attributedUnknownDe PereWisconsinCompany confirmed a cyberattack caused the outage.

The numbers of attacks are certainly far higher than reported

What’s not included in this cyberattack data

Data on cyberattacks is often not made public by private institutions, and, sometimes public ones. Private institutions have more incentive to keep details quiet. Public institutions, or private institutions that serve large numbers of people (like private hospitals or universities) have to weigh the risk of not disclosing that vital records or information may have been compromised.

Keeping quiet can protect an entity’s short-term financial interests, and is sometimes recommended by law enforcement as a means of “not giving attention” to attackers. A 2025 attack on Grand Forks, North Dakota schools provided limited details at the request of law enforcement. But that attack reportedly involved wire fraud and an ACH charge, which could potentially involve internal staff.

Still, attackers rarely want attention, and if they do it’s easy to get it. Instead, attackers are almost always motivated by money, usually in untraceable Bitcoin (virtual currency). This is why most attackers do leave systems alone or restore data if a ransom is paid. Think of it as a sort of pirate’s code: it harms other pirates if victims know or assume that whether they pay or not is irrelevant, so why bother paying if the damage is inevitable?

As one example, also from the North Dakota, a school district there mistakenly paid a contractor $1.8 million while the school was undergoing a large renovation project. The district said it was the victim of a โ€œsophisticated phishing email containing false payment instructions that appeared to come from a trusted vendor.โ€

The actual number of cyberattacks is almost unknowable

Cyberattacks, like domestic violence and many other “personal” crimes are tragically difficult to report, often because of shame, fear, embarrassment, or the fear of future harassment.

It is also almost unknowable how many cyberattacks are in the works or were even accidentally prevented.

What is known is most attacks start with a phishing or spear-phishing campaign against small groups of internal employees.

  1. One of those employees clicks a link, downloads an attachment, or somehow executes code that implants itself on a network or machine.
  2. The malware may remain dormant for many months, or even years.
    1. It may be quietly recording information and sending it to some server elsewhere for review, like keystrokes or patterns for when a user logs in or logs off.
    2. The more time that passes, the more difficult it becomes to remember how it may have started. An employee is unlikely to remember a random email from six months ago that, since then, has done seemingly nothing.
  3. The malware may activate either based on time, like a bomb, or remotely based on an attacker’s perception of detection risk. For instance, an attacker is less likely to begin a more robust cyberattack at noon on a Wednesday when the most amount of IT, security, and support staff are likely available.

It is also possible many attacks were thwarted by accident, where dormant malware sits on a machine that coincidentally gets replaced, or perhaps the hardware fails and is removed from the network.

Targeted hardware can include printers, phones, routers, and more

Much of the focus on cyberattacks is on computers, like Windows 10 or 11 PCs and Macs. But almost every device with Bluetooth, Wi-Fi, or a screen can be considered a computer. Certainly smart phones, but also smart hubs for lights, old routers that are rarely replaced or updated until they fail, printers, even VoIP phones can all be targets that enable access to a network.

Still, the weakest link in cybersecurity is almost always humans. It’s the phone call, text message, or email that contains a link or threat you don’t quite notice. AI tools are going to make this more challenging to spot as emails that were once written with poor English and grammar are now near-perfect. Or phone calls that can be emulated using AI that synthesizes a target’s voice from YouTube or other public videos.

Prepare for when, not if, an attack is possible in your facility or organization

The federal government rates cyberattacks on a scale commensurate with the overall damage and harm to life and property. A Level 5 Black emergency would result in a State of Emergency, whereas a Level 1 Green emergency poses low risk. The chart was introduced in 2016, but can be used internally at your facility.

A scale graphic indicating severity of cyber attacks and their observed actions and intended consequences.

Like knowing what to do in case of a fire or other emergency, it’s time to elevate your cyber preparedness at all levels of attack potential. VPC provides realistic training scenarios and tabletop exercises that test your team’s ability to respond to threats as they happen. This includes

  • How to maintain operations
  • What to do system-wide as teams observe and prepare for possible attacks
  • Serve customers or patients
  • Provide timely updates and notifications to the press
  • How to interact with other agencies and partners, and inform stakeholders.

Request a free consult

No-risk, no-hassle consults on options that scale to your team and organization.
Get a Quote

We've worked with these and dozens of other partners across the U.S.

Indiana District 3 HCC
Hospital Planning and preparedness corp District 6
D7 Healthcare Coalition
Indiana DHS logo featuring American flag design and eagle emblem.
Nebraska Plains Healthcare Coalition
District 10 Healthcare Coalition Logo
Southeastern Pennsylvania Healthcare Coalition Logo

Name(Required)