DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Ransomware attack affects Michigan casinos and tribal health centers

Posted on February 17, 2025February 16, 2025 by Dissent

On February 15, the RansomHub ransomware group claimed responsibility for an attack on the Sault Ste. Marie Tribe of Chippewa Indians. RansomHub claims to have “temporarily locked” the tribe’s infrastructure and to have acquired 119 GB of files (501, 211 files). The affected systems reportedly include casinos, convenience stores, government buildings, and telecommunications services, but also health centers in Sault Ste. Marie, St. Ignace, Manistique, Munising, Escanaba, and Hessel, as well as traditional medicine program facilities.

On their dark web leak site, RansomHub posts some proof of claims and blamed its victims for the situation, writing, in part:

We waited an entire week for Sault Tribe of Chippewa Indians to engage in negotiations, but no communication was initiated. This demonstrates a blatant disregard for the personal data of their residents, customers, and employees of casinos, medical centers, and other breached institutions. Their careless data storage methods have left them exposed, and their failure to respond only confirms their indifference.

They also blamed the tribe’s insurers:

Notably, their insurance providers:

  • Corvus Insurance by Travelers
  • Crum & Forster Specialty Insurance Company
  • Cowbell Cyber Risk Insurance

Typically conduct an investigation and engage in negotiations to prevent data leaks and mitigate damage. This is standard practice for minimizing financial losses and ensuring data security. However, in this case, they failed to act, allowing the situation to escalate further.

And for good measure, they also blamed the Board of Directors:

We made multiple attempts to contact the Board of Directors via email and phone. No response was received. This lack of action proves that they, too, do not care about protecting the personal data of their residents and clients at casinos, medical centers, and other compromised institutions.

RansomHub threatens to leak all data if they get no response by Wednesday. It seems highly likely that the the Sault Ste. Marie Tribe of Chippewa Indians is not going to respond if they have not responded already to all the pressure tactics that RansomHub has tried.

Sault Ste. Marie Tribe of Chippewa Indians Statement

For its part, the the Sault Ste. Marie Tribe of Chippewa Indians has issued a press release, reproduced below:

SAULT STE. MARIE, Mich. – On Sunday, Feb. 9, the Sault Ste. Marie Tribe of Chippewa Indians was the victim of a ransomware cyber attack impacting multiple phone and computer systems across tribal administration, health centers and various businesses, including the Kewadin casinos.

Tribal Chairman Austin Lowes is issuing the following update to the community on the tribe’s restoration efforts:

“We understand and share in our community’s frustration with this attack and the interruptions it has caused. I want to assure everyone that the tribe is working with cyber security experts and burning the candles at both ends to resolve this issue as quickly as possible.

“While progress has not been as fast as we would like, there is measurable progress, including the establishment of new phone numbers that have been posted to our tribe’s Facebook page. Right now, we expect the tribe will continue to operate in a limited capacity for up to another week. Regular updates will continue to be made on our Facebook page as restoration efforts progress.

“We also understand there is a desire for our membership to know the details of what happened and the specifics around what is being done to fix it. Unfortunately, given that this is an ongoing attack, we cannot share further detail at this time.

“We greatly appreciate everyone’s patience and understanding as we work through this difficult issue. As it does with any challenge our people have faced, I am confident that our tribe will emerge stronger.”

Category: Business SectorHealth DataMalwareU.S.

Post navigation

← Bill raising the bar for class-action suits in data breach incidents advances
The Myth of Jurisdictional Privacy →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Banks Want SEC to Rescind Cyberattack Disclosure Requirements
  • MathWorks, Creator of MATLAB, Confirms Ransomware Attack
  • Russian hospital programmer gets 14 years for leaking soldier data to Ukraine
  • MSCS board renews contract with PowerSchool while suing them
  • Iranian Man Pleaded Guilty to Role in Robbinhood Ransomware
  • Developments surrounding data breach at Dutch police
  • Estonia launches international search for Moroccan citizen wanted over data theft
  • Now it’s Tiffany: Another LVMH luxury brand hit by hackers
  • Dutch Government: More forms of espionage to be a criminal offence from 15 May onwards
  • B.C. health authority faces class-action lawsuit over 2009 data breach (1)

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • The CCPA emerges as a new legal battleground for web tracking litigation
  • U.S. Spy Agencies Are Getting a One-Stop Shop to Buy Your Most Sensitive Personal Data
  • Period Tracking App Users Win Class Status in Google, Meta Suit
  • AI: the Italian Supervisory Authority fines Luka, the U.S. company behind chatbot “Replika,” 5 Million €
  • D.C. Federal Court Rules Termination of Democrat PCLOB Members Is Unlawful
  • Meta may continue to train AI with user data, German court says
  • Widow of slain Saudi journalist can’t pursue surveillance claims against Israeli spyware firm

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.