Madera hospital breach touches 150,000 as extortion demand drops

The group behind a May 2025 intrusion at Madera Community Hospital withdrew its ransom demand after learning the target was a hospital.

MedRisk Staff
By
2 Min Read

A California hospital is notifying just over 150,000 people that their personal, financial, and medical information was compromised in an intrusion that took an unusual turn: the extortion group behind it withdrew its ransom demand after learning the target was a hospital.

Madera Community Hospital, a nonprofit acute care provider serving Madera County, detected unauthorized access to its network on May 29, 2025, and determined a third party had accessed the network over two days and likely acquired files. The hospital said the group claimed responsibility and demanded an extortion payment, then backed off, saying it did not want to harm patients.

The hospital received the results of a data review in April 2026 and began notifying potentially impacted individuals in mid-July. It reported 150,810 affected people to the US Department of Health and Human Services.

Exposed data may include names, contact information, dates of birth, Social Security numbers, account credentials, financial account information, treatment and health insurance details, and limited biometric information. The hospital said it has found no evidence the information was shared or released publicly, or that it has been misused.

The incident shows the unpredictable economics of healthcare extortion: while most operators press hospitals for payment because patient data is sensitive, some groups calculate that the political and legal heat of targeting a hospital is not worth the payout. Madera said it worked with third-party experts, secured its systems, and notified law enforcement.

Share This Article