743,000 McLaren Health Care Patients Exposed in Massive Ransomware Attack


# McLaren Health Care Suffers Second Major Data Breach, 743,000 Patients Affected

McLaren Health Care has notified 743,000 patients of a significant data breach following a ransomware attack by the INC cybercriminal group in July 2024. The nonprofit health system, which generates $6.6 billion in annual revenue and operates 14 hospitals across Michigan with 2,624 beds, discovered the attack on August 5, 2024.

## Attack Timeline and Discovery

The ransomware attack occurred between July 17 and August 3, 2024, but forensic investigations to determine affected patients weren’t completed until May 5, 2025. Patient notifications began last Friday, nearly 10 months after the initial breach.

During the attack, McLaren experienced widespread IT and phone system outages that disrupted hospital operations. Patients were advised to bring appointment and medication information when visiting facilities. Evidence of the INC ransomware group’s involvement surfaced when ransom notes were automatically printed on hospital printers at McLaren’s Bay City, Michigan location.

## Scope and Impact

McLaren Health Care operates an extensive network serving Michigan and Indiana, employing 490 physicians and 28,000 full-time staff while contracting with 113,000 additional providers. The breach affected both McLaren Health Care and the affiliated Karmanos Cancer Institute.

While the organization confirmed that full names were exposed, other compromised data types remain undisclosed in public notifications, leaving the complete scope of the breach unclear.

## Pattern of Vulnerability

This marks McLaren’s second major cybersecurity incident in recent years. In July 2023, the ALPHV/BlackCat ransomware group breached the system, stealing sensitive medical data, personal information, and Social Security numbers of 2.2 million people. That attack resulted in data samples being leaked online in October 2023 as part of an extortion campaign, ultimately forcing McLaren to pay an undisclosed ransom.

## Organizational Response

In patient notifications, McLaren acknowledged the attack came from “an international ransomware group” but did not specifically name the INC group. The organization has implemented security measures following both incidents, though the recurrence suggests ongoing cybersecurity challenges for the healthcare provider.

The repeated targeting of McLaren highlights the persistent threat ransomware groups pose to healthcare organizations, which often possess valuable patient data and face pressure to restore critical systems quickly.

Share This Article