Search, filter, and sort attacks known near your location

In the last five years, starting March 31, 2021 through March 31, 2026, there were 43 confirmed cyberattacks in the Midwest. One attack was attempted and one other was suspected. If that seems low, it’s because it is. And in the time since we compiled this list and this publication, Iranian-linked hackers have claimed control of the St. Joseph County, Indiana (home of South Bend and Notre Dame University) infrastructure, records, and systems.
How we compiled data on cyberattacks
Looking at publicly-available data we compiled a list by looking at public press releases, news reports, public government reports, and, in some cases, public notices from the attackers.
- We only sought information on large-scale industries, healthcare facilities, schools, and commercial operations.
- Small businesses under 50 people and individuals are not included.
- We only looked at information available in 12 Midwest states (IA, IL, IN, KS, MI, MN, MO, ND, NE, OH, SD, WI)
| Organization | Sector | Incident Date | Attack Type | Impact Summary | Attacker / Group | Attribution Status | Attributed Origin / Nexus | City / Town | State | Notes |
|---|---|---|---|---|---|---|---|---|---|---|
| NEW Cooperative | Agriculture / food supply | 2021-09-20 | Ransomware / operational disruption | Agricultural cooperative suffered a ransomware event with supply-chain concerns. | BlackMatter | Claimed by attacker / reported | Russian-speaking / Russia-linked | Fort Dodge | Iowa | Often described in reporting as a Russia-linked or Russian-speaking ransomware operation. |
| Des Moines Public Schools | Education | 2023-01-09 | Ransomware / data theft | District took networked systems offline and later confirmed stolen data. | Unnamed ransomware group | Victim confirmed ransomware but did not publicly name group in cited source | Unknown | Des Moines | Iowa | District said it received but did not pay a ransom demand. |
| Clarke County Hospital | Healthcare | 2023-04-14 | Ransomware / data breach | Hospital shut down network access and later disclosed exposure of patient data. | Royal | Claimed by attacker / reported | Unknown / not publicly specified in cited source | Osceola | Iowa | Royal leak-site claim was reported after the attack. |
| City of Cedar Falls | Government | 2024-06-19 | Ransomware / data breach | Municipal breach led to resident notifications and compromised SSNs. | BlackSuit | Claimed by attacker / reported | Unknown / not publicly specified in cited source | Cedar Falls | Iowa | Comparitech reported BlackSuit claimed the incident. |
| Ann & Robert H. Lurie Children's Hospital of Chicago | Healthcare | 2024-01-31 | Cyberattack / suspected ransomware | Weeks-long network outage affecting records, phones, and operations. | Rhysida | Claimed by attacker / hospital said known criminal threat actor | Unknown / not publicly specified in cited source | Chicago | Illinois | Hospital confirmed a known criminal threat actor; Rhysida was reported as the claiming group. |
| Community High School District 117 | Education | 2024-06-02 | Unauthorized access / data breach | District disclosed a June 2024 network intrusion affecting thousands. | BlackSuit | Claimed by attacker / not independently verified | Unknown; group described in reporting as having Russian lineage | Lake Villa | Illinois | Comparitech cites district notice for unauthorized access between June 2 and June 12, 2024. |
| CDK Global | Technology / auto retail software | 2024-06-19 | Ransomware / service disruption | Dealer management software outages disrupted thousands of auto dealerships. | BlackSuit | Believed / reported | Unknown / not publicly specified in cited source | Hoffman Estates | Illinois | Attribution based on reporting and analyst statements; CDK did not publicly confirm the group in cited source. |
| Crystal Lake Elementary District 47 | Education | 2024-10-17 | Network disruption / data breach | District reported a network disruption and later notified victims of a data breach. | RansomHub | Claimed by attacker / not independently verified | Unknown / not publicly specified in cited source | Crystal Lake | Illinois | Incident date reflects district notice date for the network disruption. |
| Logansport Community School Corporation | Education | 2021-04-01 | Ransomware / data theft | Sensitive student and staff information exposed after district attack. | Pysa | Claimed by attacker / reported | Unknown / not publicly specified in cited source | Logansport | Indiana | Month approximate from public reporting. |
| Johnson Memorial Health | Healthcare | 2021-10-01 | Ransomware | Hospital operations disrupted; ambulance diversions; extended downtime and paper records. | Hive | Publicly attributed | Unknown / not publicly specified in cited source | Franklin | Indiana | Attack described as beginning in October 2021. |
| Monroe County Government | Government | 2024-07-01 | Ransomware / network intrusion | County services and systems were disrupted for about a week. | BlackSuit | Publicly attributed | Russian Federation (per public reporting on group affiliation) | Bloomington | Indiana | County publicly tied outage to BlackSuit. |
| Clay County Government | Government | 2024-07-01 | Ransomware | County issued a disaster declaration after servers were hit. | LockBit | Claimed by attacker / not independently verified | Unknown / not publicly specified in cited source | Brazil | Indiana | LockBit claim was reported after the county incident. |
| Indiana University Health | Healthcare | 2024-10-18 | Email compromise / data breach | Unauthorized access to a team member email account exposed limited patient data. | Unknown | Not publicly attributed | Unknown | Indianapolis | Indiana | Date reflects initial detection date in official notice. |
| Kansas Judicial Branch | Government / judiciary | 2023-10-12 | Ransomware / data theft | Court systems were disrupted in a major statewide judicial cyberattack. | Affiliates of a Russian-based ransomware group | Publicly attributed | Russian-based | Topeka | Kansas | State officials publicly said affiliates of a Russian-based group were responsible. |
| Unified Government of Wyandotte County / Kansas City, Kansas Police Department | Government / public safety | 2024-05-01 | Cyberattack / service disruption | Police and broader municipal services were disrupted by a network incident. | BlackSuit | Claimed by attacker / not independently verified | Unknown / not publicly specified in cited source | Kansas City | Kansas | Comparitech reported BlackSuit claimed the incident. |
| City of Wichita | Government | 2024-05-05 | Ransomware / municipal service disruption | City services were disrupted after a ransomware attack. | LockBit | Claimed by attacker / reported | Unknown / not publicly specified in cited source | Wichita | Kansas | LockBit claim reported after the Wichita incident. |
| McLaren Health Care | Healthcare | 2023-08-01 | Ransomware / data theft | Large breach and operational disruption affected multiple McLaren facilities. | ALPHV / BlackCat | Claimed by attacker / reported | Unknown / not publicly specified in cited source | Grand Blanc | Michigan | Month approximate; public reports tied the 2023 attack to ALPHV/BlackCat. |
| Grand Traverse County / City of Traverse City | Government | 2024-06-12 | Ransomware | County and city government systems went offline after a ransomware incident. | Unknown | Not publicly attributed | Unknown | Traverse City | Michigan | Local reporting later identified the outage as a ransomware attack. |
| McLaren Health Care | Healthcare | 2024-08-01 | Ransomware / data theft | Second major McLaren cyber incident in two years disrupted systems and exposed data. | INC Ransom | Claimed by attacker / reported | Unknown / not publicly specified in cited source | Grand Blanc | Michigan | Separate 2024 incident reported after the earlier 2023 McLaren event. |
| Wayne County Government | Government | 2024-10-01 | Cyberattack / service disruption | Major county systems were affected in Michigan's largest county. | Unknown | Not publicly attributed | Unknown | Detroit | Michigan | Month approximate from public reporting. |
| Stryker | Manufacturing / medical devices | 2026-03-11 | Cyberattack / destructive disruption | Global network disruption affected ordering, shipping, and manufacturing. | Handala | Claimed by attacker / reported | Iran-linked | Portage | Michigan | Company said no malware or ransomware was involved; Handala publicly claimed the attack. |
| University of Minnesota | Higher education | 2021-07-21 | Unauthorized access / data breach | University disclosed unauthorized access affecting personal information. | Unknown | Not publicly attributed | Unknown | Minneapolis | Minnesota | Official FAQ says access likely occurred in 2021; disclosure came later. |
| St. Paul Public Schools | Education | 2023-02-15 | Unauthorized access / data breach | District warned families after a data security incident affecting student information. | Unknown | Not publicly attributed | Unknown | St. Paul | Minnesota | Date approximate; suspicious activity was disclosed in 2023. |
| Minnesota Department of Education | Government / education | 2023-05-31 | File-transfer exploitation / data breach | Large student-data breach tied to a wider file-transfer software campaign. | Unknown | Not publicly attributed in cited source | Unknown | St. Paul | Minnesota | Breach was publicly linked to the wider MOVEit campaign, but no group is named in the cited source. |
| City of Saint Paul | Government | 2025-07-25 | Ransomware | Major municipal digital security incident disrupted city systems and services. | Interlock | Claimed by attacker / reported | Unknown / not publicly specified in cited source | St. Paul | Minnesota | Official city hub describes it as part of a growing wave of ransomware attacks; Interlock attribution came from external reporting. |
| Missouri Delta Medical Center | Healthcare | 2021-09-01 | Ransomware / data theft | Hospital reported ransomware incident and patient data exposure. | Hive | Claimed by attacker / reported | Unknown / not publicly specified in cited source | Sikeston | Missouri | Month approximate from public reporting. |
| University of Central Missouri | Higher education | 2024-02-07 | Attempted cyberattack | University took IT systems offline following an attempted attack on servers. | Unknown | Not publicly attributed | Unknown | Warrensburg | Missouri | University described the event as an attempted cyberattack. |
| Jackson County Government | Government | 2024-04-02 | Suspected ransomware / service disruption | County offices closed and multiple public services were rendered inoperative. | Unknown | Suspected only | Unknown | Kansas City | Missouri | Officials initially described the incident as potentially attributable to ransomware. |
| Pembina County Memorial Hospital | Healthcare | 2023-04-13 | External system breach / data theft | Hospital disclosed an external system breach affecting employee and patient data. | Unknown | Not publicly attributed | Unknown | Cavalier | North Dakota | Hospital said an unauthorized party obtained access to its internal network. |
| Grand Forks Public Schools | Education | 2024-09-01 | Phishing / wire fraud | District lost about $2.2 million through a fraudulent ACH payment change. | Unknown | Not publicly attributed | Unknown | Grand Forks | North Dakota | Month approximate from public reporting. |
| Dickinson Public Schools | Education | 2026-02-11 | Vendor impersonation / business email compromise | Sophisticated email scam redirected nearly $5 million. | Unknown | Not publicly attributed | Unknown | Dickinson | North Dakota | Public reporting described a sophisticated impersonation and invoice-fraud scheme. |
| Douglas County 911 | Government / public safety | 2022-10-04 | Ransomware / cryptovirus | Emergency communications operations were affected by a cryptovirus. | Unknown | Not publicly attributed | Unknown | Omaha | Nebraska | The incident affected public safety systems. |
| Nebraska Judicial Branch | Government / judiciary | 2023-06-01 | Hack / unauthorized access | Internal intranet systems were hacked, but the judiciary said no data was lost. | Unknown | Not publicly attributed | Unknown | Lincoln | Nebraska | Month approximate from public reporting. |
| Winnebago Public Schools | Education | 2024-10-21 | Cyberattack / school outage | School district cancelled classes after cyberattack shut down systems. | Interlock | Claimed by attacker / reported | Unknown / not publicly specified in cited source | Winnebago | Nebraska | Interlock claim was reported in later coverage. |
| Broken Bow Public Schools | Education | 2025-02-01 | Business email compromise / wire fraud | District lost more than $1 million in a phishing-driven scam. | Unknown | Not publicly attributed | Unknown | Broken Bow | Nebraska | Month approximate from public reporting. |
| Memorial Health System | Healthcare | 2021-08-15 | Ransomware | Ambulance diversions and cancellations followed a major hospital outage. | Hive | Claimed by attacker / reported | Unknown / not publicly specified in cited source | Marietta | Ohio | Public reporting tied the August 2021 incident to Hive. |
| City of Cleveland | Government | 2024-06-01 | Ransomware | City Hall and other systems were disrupted by a ransomware incident. | Unknown | Not publicly attributed | Unknown | Cleveland | Ohio | Month approximate from public reporting. |
| City of Columbus | Government | 2024-07-18 | Ransomware / data breach | City breach led to notification of hundreds of thousands of residents. | Rhysida | Claimed by attacker; city separately said foreign cyber threat actor | Foreign actor (not publicly named by city) | Columbus | Ohio | Rhysida claim was reported; city used broader foreign-actor language. |
| Kettering Health | Healthcare | 2025-05-20 | Ransomware / data theft | System-wide outage disrupted procedures, EHR access, phones, and scheduling. | Interlock | Publicly attributed | Unknown / not publicly specified in cited source | Kettering | Ohio | Kettering later said it had reason to believe Interlock launched the attack. |
| Brown County Government | Government | 2021-07-01 | Phishing / network shutdown | A scam-link click shut down most of the county network for over a week. | Unknown | Not publicly attributed | Unknown | Aberdeen | South Dakota | Summer 2021 incident; date approximate. |
| Black Hills Regional Eye Institute | Healthcare | 2025-01-08 | Hacking / data theft / ransomware claim | Unauthorized party accessed and acquired patient information after a network incident. | Qilin | Claimed by attacker / reported | Unknown / not publicly specified in cited source | Rapid City | South Dakota | Official notice was posted on the organization's website on Aug. 29, 2025. |
| Group Health Cooperative of South Central Wisconsin | Healthcare | 2024-01-25 | Data theft / attempted encryption | More than 500,000 records affected after a cyberattack and attempted encryption. | BlackSuit | Claimed by attacker / reported | Foreign ransomware gang | Madison | Wisconsin | Reporting described the actor as a foreign ransomware gang; later reporting tied the claim to BlackSuit. |
| Waupaca County School District | Education | 2024-05-01 | Cyberattack / possible ransomware | School district experienced a cyber incident later claimed by a ransomware gang. | Fog | Claimed by attacker / not independently verified | Unknown / not publicly specified in cited source | Waupaca | Wisconsin | Month approximate from public reporting. |
| City of Sheboygan | Government | 2024-10-31 | Ransomware / data breach | Municipal systems disrupted; later breach notices indicated large resident impact. | Chort | Claimed by attacker / reported | Unknown / not publicly specified in cited source | Sheboygan | Wisconsin | Later reporting associated the incident with Chort. |
| Cellcom | Telecommunications | 2025-05-14 | Cyberattack / service outage | Extended outage affected voice and text services for Wisconsin customers. | Unknown | Not publicly attributed | Unknown | De Pere | Wisconsin | Company confirmed a cyberattack caused the outage. |
The numbers of attacks are certainly far higher than reported
What’s not included in this cyberattack data
Data on cyberattacks is often not made public by private institutions, and, sometimes public ones. Private institutions have more incentive to keep details quiet. Public institutions, or private institutions that serve large numbers of people (like private hospitals or universities) have to weigh the risk of not disclosing that vital records or information may have been compromised.
Keeping quiet can protect an entity’s short-term financial interests, and is sometimes recommended by law enforcement as a means of “not giving attention” to attackers. A 2025 attack on Grand Forks, North Dakota schools provided limited details at the request of law enforcement. But that attack reportedly involved wire fraud and an ACH charge, which could potentially involve internal staff.
Still, attackers rarely want attention, and if they do it’s easy to get it. Instead, attackers are almost always motivated by money, usually in untraceable Bitcoin (virtual currency). This is why most attackers do leave systems alone or restore data if a ransom is paid. Think of it as a sort of pirate’s code: it harms other pirates if victims know or assume that whether they pay or not is irrelevant, so why bother paying if the damage is inevitable?
As one example, also from the North Dakota, a school district there mistakenly paid a contractor $1.8 million while the school was undergoing a large renovation project. The district said it was the victim of a โsophisticated phishing email containing false payment instructions that appeared to come from a trusted vendor.โ
The actual number of cyberattacks is almost unknowable
Cyberattacks, like domestic violence and many other “personal” crimes are tragically difficult to report, often because of shame, fear, embarrassment, or the fear of future harassment.
It is also almost unknowable how many cyberattacks are in the works or were even accidentally prevented.
What is known is most attacks start with a phishing or spear-phishing campaign against small groups of internal employees.
- One of those employees clicks a link, downloads an attachment, or somehow executes code that implants itself on a network or machine.
- The malware may remain dormant for many months, or even years.
- It may be quietly recording information and sending it to some server elsewhere for review, like keystrokes or patterns for when a user logs in or logs off.
- The more time that passes, the more difficult it becomes to remember how it may have started. An employee is unlikely to remember a random email from six months ago that, since then, has done seemingly nothing.
- The malware may activate either based on time, like a bomb, or remotely based on an attacker’s perception of detection risk. For instance, an attacker is less likely to begin a more robust cyberattack at noon on a Wednesday when the most amount of IT, security, and support staff are likely available.
It is also possible many attacks were thwarted by accident, where dormant malware sits on a machine that coincidentally gets replaced, or perhaps the hardware fails and is removed from the network.
Targeted hardware can include printers, phones, routers, and more
Much of the focus on cyberattacks is on computers, like Windows 10 or 11 PCs and Macs. But almost every device with Bluetooth, Wi-Fi, or a screen can be considered a computer. Certainly smart phones, but also smart hubs for lights, old routers that are rarely replaced or updated until they fail, printers, even VoIP phones can all be targets that enable access to a network.
Still, the weakest link in cybersecurity is almost always humans. It’s the phone call, text message, or email that contains a link or threat you don’t quite notice. AI tools are going to make this more challenging to spot as emails that were once written with poor English and grammar are now near-perfect. Or phone calls that can be emulated using AI that synthesizes a target’s voice from YouTube or other public videos.
Prepare for when, not if, an attack is possible in your facility or organization
The federal government rates cyberattacks on a scale commensurate with the overall damage and harm to life and property. A Level 5 Black emergency would result in a State of Emergency, whereas a Level 1 Green emergency poses low risk. The chart was introduced in 2016, but can be used internally at your facility.

Like knowing what to do in case of a fire or other emergency, it’s time to elevate your cyber preparedness at all levels of attack potential. VPC provides realistic training scenarios and tabletop exercises that test your team’s ability to respond to threats as they happen. This includes
- How to maintain operations
- What to do system-wide as teams observe and prepare for possible attacks
- Serve customers or patients
- Provide timely updates and notifications to the press
- How to interact with other agencies and partners, and inform stakeholders.










