University of Hawaiʻi Cancer Center confirms leak after ransomware attack

THE BRIEF
The University of Hawaiʻi Cancer Center has confirmed a data leak following a ransomware attack, according to The Record from Recorded Future News. Part of the exposed information was traced to the Multiethnic Cohort (MEC) Study, which was established in 1993. The study used driver’s license numbers and voter registration records to recruit participants. The supplied report does not specify how many people were affected, which records were accessed or disclosed, when the ransomware attack occurred, or whether the leaked information has been published or misused. It also does not identify the attackers or provide details about the intrusion, response, or recovery. The MEC connection is significant because the study’s recruitment process involved identity-related information collected for research participation. The confirmation therefore links the ransomware-related leak to records associated with a long-running cancer research effort, while leaving the full scope and consequences unresolved. Organizations reviewing this incident should distinguish between the confirmed leak, the reported connection to MEC records, and details that have not been provided in the supplied account.
WHY IT MATTERS
This incident connects a ransomware-related data leak at a cancer center with records from the Multiethnic Cohort Study, established in 1993 and described as using driver’s license numbers and voter registration records to recruit participants. That combination highlights the sensitivity and longevity of research data without establishing the full scope of exposure. The supplied facts do not say how many individuals were affected, what information was leaked, or whether the data was misused. Those unknowns make careful verification and measured communication important for organizations handling historic research records.
WHO SHOULD CARE
Healthcare providers, cancer researchers, universities, privacy teams, and incident responders should care because the reported leak involved a cancer center and was partly traced to a long-running study using identity-related recruitment records. They should avoid assuming a broader impact than the supplied facts establish.
WHAT TO DO NOW
- Inventory historic research datasets and document what identity-related information they contain.
- Verify whether records connected to the Multiethnic Cohort were accessed or disclosed, without assuming broader exposure.
- Coordinate legal, privacy, research, and communications teams around confirmed facts and unresolved questions.