HomeSecurityUniversity of Hawaii: Breach at Cancer Center exposed important data

University of Hawaii: The breach at the Cancer Center exposed significant data

The University of Hawaii is dealing with the fallout from a recent cyberattack on its Cancer Center. The breach affected research systems at the university's Cancer Center and potentially exposed sensitive personal data, including social security numbers and driver's license numbers, that were collected decades ago for epidemiological research. According to an official report, the data breach was discovered in December 2025.

University of Hawaii: The breach at the Cancer Center

However, the cybersecurity incident was first identified around August 31, 2025.

The attack ransomware was limited to specific servers supporting research operations at the Cancer Center. The University of Hawaii confirmed that the cyberattack did not impact clinical operations, patient care or medical records. There was also no impact on student records or other addresses within the University’s system.

See also: OnlyFake: Ukrainian confessed to selling fake AI identities

The affected data was strictly contained within research files and was not linked to patient treatment records. During the cyberattack, an unauthorized user encrypted and potentially extracted data from certain research servers. The compromised files included:

  • Two files containing names combined with social security numbers.
  • One file included driver's license numbers collected in 2000 by the state Department of Transportation. At the time, driver's license numbers were typically based on Social Security numbers.

University of Hawaii: How many were affected by the breach?

The cyberattack on the Cancer Center may have affected 87,493 participants in the Multiethnic Cohort Study. The MEC Study has used more than 215,000 men and women aged 45 to 75 from 1993 to 1996. The participants came from five major racial and ethnic groups residing in Hawaii and Los Angeles, California.

In addition, three epidemiological studies focusing on diet and cancer were affected, specifically colorectal adenomas (from 1995 to 2007) and colorectal cancer (1994-2005).

See also: 10 simple ways to protect your personal data in 2026

University of Hawaii: The breach at the Cancer Center exposed significant data

These files included names combined with Social Security numbers and/or driver's license numbers. Some files also included participant questionnaires, survey data health-related , and information from national and state public health registries. Two additional files containing names and Social Security numbers, collected from public health registries, were also compromised.

One of these files stopped accepting new names in 1999, while the other was closed in the mid-2000s. In addition to the 87,493 MEC participants, an additional 1.15 million people may be affected, as some of their information was in historical driver's license and voter registration that contained Social Security IDs. Investigations are ongoing to determine whether other sensitive data was involved.

University of Hawaii has stated that affected users will be notified individually, where possible.

How did the University respond to the attack?

After the discovery of the cyberattack on the Cancer Center, the University immediately disconnected the affected systems and worked to terminate unauthorized access. Cybersecurity experts were hired to investigate the extent of the breach. Due to the extensive encryption deployed by the threat actors, restoring the systems took time.

During the investigation, it was determined that an unauthorized third party had access to and was able to extract a subset of research files. While the review was ongoing, the university decided to work with the threat actors in an effort to protect those affected. Working with cybersecurity experts, the University of Hawaii obtained a decryption tool and secured confirmation that the stolen data was destroyed.

See also: North Koreans published 26 malicious npm packages for RAT distribution

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

So far, officials report that there is no evidence that the information has been published, shared, or misused.

University of Hawaii: The breach at the Cancer Center exposed significant data

Initially, most of the affected records appeared to contain research data without personal identifiers. However, a more detailed online review confirmed the presence of records dating back to the 1990s that contained social security numbers used at that time to identify research participants. Following confirmation of the report, the University of Hawaii initiated notification proceedings pursuant to §487N-4 of the Hawaii Revised Statutes.

On February 23, notification letters were sent to 87,493 MEC Study participants. The University also identified approximately 900,000 email addresses and is providing notification via electronic communication, public announcement, and an Information and Resources Website.

The university is offering those affected 12 months of free credit monitoring. Officials have advised the public to rely only on updates posted through official University channels and to ignore messages requesting personal information.

See also: ScarCruft uses Zoho WorkDrive and USB malware to compromise air-gapped networks

University of Hawaii: The breach at the Cancer Center exposed significant data

Extensive cybersecurity upgrades

In response to the cyberattack on the Cancer Center, the University of Hawaii has implemented extensive cybersecurity upgrades. These measures include:

  • Installation of endpoint protection software with 24/7 monitoring
  • Password reset and replacement of affected user accounts
  • Transfer of sensitive research servers to the UH Information Services data center
  • Conducting third‑party security assessments
  • Strengthening stricter access controls and mandatory cybersecurity training

Additionally, the University of Hawaii created a new Information Technology Governance Council for Research and established an Information Security Working Group to inform policies, strengthen cybersecurity roles, and propose enterprise-wide controls.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS