Mon General confirms phishing breach exposed patient email accounts

West Virginia's Mon General says phishing replies handed attackers employee mailboxes holding patient data.

MedRisk Staff
By
1 Min Read

Phishing emails duped employees at Mon General, the West Virginia hospital company formally known as Monongalia County General Hospital Company, into surrendering their login credentials. Attackers used them to reach a small number of employee mailboxes; the company detected the activity on May 6, 2026, and a digital forensics firm confirmed the intrusion stayed within those accounts.

The compromised inboxes held patient information, including names, birth dates, phone numbers, Social Security numbers, and health and insurance details. Notification letters are going out now, with two years of credit monitoring and identity theft protection offered to those affected; the total affected count has not been released.

The case is a reminder that credential phishing remains a primary entry point into healthcare email systems, with a single compromised mailbox able to expose protected health information for months. Mon General, which operates a hospital in Morgantown and clinics across north-central West Virginia, joins a growing list of providers whose email accounts were the breach surface. Phishing-resistant multifactor authentication, least-privilege mailbox access, and monitoring for impossible travel and suspicious forwarding rules are the practical defenses against this pattern.

Share This Article