Idaho Hospital Disrupted on Easter; Blackwater Ransomware Claims 577GB Stolen
Minidoka Memorial Hospital transferred emergency patients after an imaging outage; a new ransomware group claims it stole 2.3 million files. The hospital has not acknowledged that claim and has never called the incident ransomware.
RUPERT, ID — A quiet Easter morning in rural Idaho was interrupted on April 5, 2026, when Minidoka Memorial Hospital (MMH) experienced what it later described as a cyber incident that "temporarily impacted certain systems" within the organization. While the hospital managed to keep its emergency department and clinics operational, the disruption to imaging services forced the critical access facility to transfer emergency patients to Cassia Regional Hospital.
Update (August 26, 2026): The following are open questions, not findings. Minidoka Memorial Hospital has still not acknowledged Blackwater's claim, and it has never characterized the incident as ransomware. The CyberSignal could not confirm whether Blackwater published the claimed data after its April 24, 2026 deadline — no reliable source establishes that it did, and none establishes that it did not. No entry for this incident carrying a final affected-individual count has been identified on the HHS Office for Civil Rights breach portal. HIPAA Journal, in coverage updated April 27, 2026, reported that the extent of unauthorized access had yet to be determined.
In an official statement released via Facebook on April 17, MMH said the facility "experienced a cyber incident on Easter morning that temporarily impacted certain systems within our organization." The hospital has consistently described the event as a cyber incident and has never used the word ransomware. Full imaging functionality was restored by midnight on April 19, 2026. The emerging ransomware group Blackwater has provided a far more detailed and aggressive narrative. On the same day the hospital issued its statement, Blackwater listed MMH on its leak site, claiming to have exfiltrated 577GB of data comprising over 2.3 million files. The hospital has not acknowledged that claim.
Breach Audit: Rural Healthcare Vulnerability
Minidoka Memorial is a 25-bed critical access hospital that also operates a nursing home in Cassia County. The attack highlights a persistent trend of threat actors targeting rural healthcare infrastructure, where resources for healthcare cybersecurity best practices are often stretched thin.
Blackwater: A New Threat to PHI
Blackwater appears to be a relatively new operation, first surfacing in March 2026, and its listings so far have skewed heavily toward the healthcare sector — leak-site tracking places MMH among roughly three healthcare organizations the group claimed in under two months. Those counts derive from Blackwater's own leak-site postings and third-party trackers rather than from confirmed incidents. The group presents itself as running a "double extortion" model — encrypting local files to disrupt operations while exfiltrating sensitive data to use as leverage for ransom payments.
That track record is itself a reason for caution. Comparitech reported that Blackwater's April 12, 2026 claim against Medical Park Hospitals Group in Turkey was denied by the hospitals — a reminder that a leak-site listing is an assertion by the attacker, not a verified breach.
The hospital has not confirmed the validity of Blackwater's 577GB data theft claim, nor has it disclosed a ransom amount. The group threatened to publish the claimed files by April 24, 2026, if its demands were not met; The CyberSignal has not been able to confirm whether any data was in fact published after that date. This incident follows a broader trend of ransomware groups targeting essential services to maximize pressure.
Comparitech, which tracked the listing, was explicit about the limits of what is actually known. Minidoka Memorial Hospital "has not acknowledged Blackwater's claim and Comparitech cannot independently verify it," the outlet wrote. "We do not know what data was compromised, if the hospital did or will pay a ransom, how much Blackwater demanded, or how attackers breached the hospital's network."
For ongoing tracking of threat actors in this space, visit our ransomware archive.
The CyberSignal Analysis
Signal 01 — The Holiday Timing
The incident began on Easter morning, and holiday timing is a recognised risk factor whatever the underlying cause turns out to be. Holiday weekends typically see reduced IT staffing levels and slower incident response, which widens the window in which an intruder can operate before anyone notices. Minidoka has not disclosed how the incident began or how far it reached inside its network. But for rural hospitals generally, that detection latency is what separates a contained problem from days of degraded service.
Signal 02 — Emerging Actor Aggression
Blackwater's rapid-fire run of claimed healthcare victims suggests a specialized "playbook" for bypassing PHI protections. If the group is behind the Minidoka outage — a link the hospital has never confirmed — then a willingness to disrupt patient care through imaging downtime would indicate a high tolerance for risk and a focus on high-pressure extortion over subtle infiltration.