Back to Blog
Technology

No Ransoms Paid in Cyberattacks on UMMC and IHL, Officials Say

By Kishan PrajapatSep 23, 2026
No Ransoms Paid in Cyberattacks on UMMC and IHL, Officials Say

Big news out of Mississippi: officials say they never paid ransoms after the ransomware hits at the University of Mississippi Medical Center and the state Institutes of Higher Learning. In short: no ransom payments, FBI-backed forensics, and lawmakers now want more answers. Meta description preview: No ransoms paid in cyberattacks on UMMC and IHL, officials say, with FBI forensic support and state audits outlining timelines and costs.

What happened, and why the refusal to pay matters? On February 19, 2026, the University of Mississippi Medical Center suffered a ransomware attack that disrupted systems and triggered a forensic response with federal involvement, according to reporting that directly cites UMMC statements and timelines [https://msindy.org/p/ummc-mum-on-talks-with-cyberattackers]. The same window of incidents affected state Institutes of Higher Learning, and local reporting confirmed that "No ransoms were paid in cyberattacks on UMMC and IHL, officials say" [https://mississippitoday.org/2026/09/22/no-ransoms-cyberattacks-ummc-ihl/]. State Senator Nicole Boyd told reporters that she has confirmed no taxpayer money was used to pay ransoms in either incident, a specific claim that narrows possible funding channels for any hypothetical payments [https://magnoliatribune.com/2026/09/22/state-auditor-seeks-details-on-cyberattacks-at-ummc-ihl/].

It looks like officials deliberately chose containment and forensics over bargaining with criminals. Refusing to pay protects evidence and keeps money out of criminals' hands, but it usually drags out recovery. The trade-off really comes down to speed versus setting a dangerous precedent.

What officials say about the incidents and the ransom question

Multiple local reports repeat the same point: officials say no ransom payments were made in the UMMC or IHL incidents [https://mississippitoday.org/2026/09/22/no-ransoms-cyberattacks-ummc-ihl/]. LouAnn Woodward, vice chancellor for health affairs at UMMC, has been named in coverage describing the hospital's response and its tight-lipped stance about direct negotiations with attackers [https://msindy.org/p/ummc-mum-on-talks-with-cyberattackers]. The State Auditor is seeking more precise details about the timeline and recovery costs after lawmakers raised questions, a sign that elected officials want numerical accountability in days and dollars [https://magnoliatribune.com/2026/09/22/state-auditor-seeks-details-on-cyberattacks-at-ummc-ihl/].

If you follow breach policy, pay attention: the FBI helped with forensics after the February 19, 2026 UMMC attack, and the review stretched into months, reopening questions about patient data exposure and system hardening [https://mississippitoday.org/2026/04/23/ummc-cyberattack-patient-data/]. That February 19 date gives us a clear starting point for the timeline. That date helps measure duration: forensic work was reported as ongoing at least into late April, which gives a recovery and investigation window of roughly 60 days, according to the reporting timeline [https://mississippitoday.org/2026/04/23/ummc-cyberattack-patient-data/].

Here's a quick pause to note the timeline matters: the first days often determine whether a breach becomes a full-blown outage.

How the response unfolded, with timelines and measurable actions

Records show UMMC cut off affected systems right after the Feb. 19 incident and, within days, started forensic work with FBI help, basically the federal playbook for preserving evidence [https://mississippitoday.org/2026/04/23/ummc-cyberattack-patient-data/]. State reporting on September 22 recorded that lawmakers and the State Auditor are pressing for a detailed accounting of how many systems were isolated, how long services were offline, and what the total recovery cost was, though exact dollar figures are still being sought [https://magnoliatribune.com/2026/09/22/state-auditor-seeks-details-on-cyberattacks-at-ummc-ihl/]. Senator Nicole Boyd explicitly said she confirmed no taxpayer funds were used to pay ransoms, a statistic that narrows one variable in the financial aftermath [https://magnoliatribune.com/2026/09/22/state-auditor-seeks-details-on-cyberattacks-at-ummc-ihl/].

The hospital gave short answers about negotiations, not surprising when law enforcement tells you to keep quiet to protect an investigation [https://msindy.org/p/ummc-mum-on-talks-with-cyberattackers]. Officials gave a before-and-after contrast: before the incident, full clinical systems were online; after, some services were routed to manual workflows or alternative systems for several weeks, and forensic analysis extended into months [https://mississippitoday.org/2026/04/23/ummc-cyberattack-patient-data/]. Practically speaking, once federal agents step in you should expect investigations to run a month or three, give or take.

Why not paying ransom was chosen, and a common misconception addressed

Experts argue, and officials echoed, that paying ransoms just fuels more attacks and hurts public safety [https://mississippitoday.org/2026/09/22/no-ransoms-cyberattacks-ummc-ihl/]. A lot of people assume paying will get systems back fast. The evidence suggests the reality is messier, because paid decryptors can be incomplete, attackers might withhold keys, and secondary data leaks remain a risk, which is why the FBI often advises against payment during active investigations [https://mississippitoday.org/2026/04/23/ummc-cyberattack-patient-data/]. Officials said their priority was forensic integrity and public accountability, not quick fixes, and lawmakers have demanded a clearer cost and impact report [https://magnoliatribune.com/2026/09/22/state-auditor-seeks-details-on-cyberattacks-at-ummc-ihl/].

Bottom line: there's no neat answer.

A concrete example of operational impact and measurable outcomes

The February 19 UMMC attack led clinicians to use paper charts and alternate communications for several days while select systems were isolated, an operational pivot that lowered electronic throughput but maintained critical care access, according to hospital statements reported in April [https://mississippitoday.org/2026/04/23/ummc-cyberattack-patient-data/]. Forensics took weeks, with reported activity continuing into April and questions still pending by September, which implies a forensic timeline of roughly 60 to 200 days depending on which milestones are measured [https://mississippitoday.org/2026/04/23/ummc-cyberattack-patient-data/], [https://mississippitoday.org/2026/09/22/no-ransoms-cyberattacks-ummc-ihl/]. Officials have not published a full inventory of affected systems or a final dollar cost yet, and the State Auditor's probe is looking to fill that gap [https://magnoliatribune.com/2026/09/22/state-auditor-seeks-details-on-cyberattacks-at-ummc-ihl/].

What institutions and individuals should do now

The reporting points to a straightforward checklist: cut off affected systems fast, call law enforcement, save forensic images, and switch critical services to tested backups. Officials said UMMC did exactly that and worked with the FBI on forensic collection, a playbook consistent with federal incident response advice [https://mississippitoday.org/2026/04/23/ummc-cyberattack-patient-data/]. To be fair, organizations must trade fast restoration against the risk of rewarding criminal behavior. The problem is there are no perfect answers, only accountable ones. I think that kind of accountability matters more than the illusion of a quick fix.

Frequently Asked Questions

Frequently Asked Questions

Q: Were any ransoms paid to the attackers? A: Officials confirmed that no ransoms were paid in the incidents affecting UMMC and IHL, and state lawmakers said no taxpayer money was used for payments, according to local reporting [https://mississippitoday.org/2026/09/22/no-ransoms-cyberattacks-ummc-ihl/], [https://magnoliatribune.com/2026/09/22/state-auditor-seeks-details-on-cyberattacks-at-ummc-ihl/].

Q: Who led the investigation and how long did forensic work take? A: The FBI supported forensic analysis after the February 19, 2026, UMMC attack, with reporting indicating investigative work continued into April and beyond, giving a practical forensic window of roughly 60 to 90 days in the visible timeline [https://mississippitoday.org/2026/04/23/ummc-cyberattack-patient-data/].

Q: What immediate steps can hospitals take to avoid paying ransoms? A: Officials and experts recommend isolating affected systems, preserving logs and disk images, activating known backups, and coordinating with law enforcement and state auditors to preserve evidence while restoring services [https://msindy.org/p/ummc-mum-on-talks-with-cyberattackers], [https://magnoliatribune.com/2026/09/22/state-auditor-seeks-details-on-cyberattacks-at-ummc-ihl/].

Don't wait: rehearse your response now.

Actionable takeaway: document and rehearse your incident-response playbook, I honestly think the hard work up front matters more than making a quick payment. These cases show refusing to pay happened at big institutions, and that choice comes with trade-offs.

1) A tense hospital IT operations center at night, multiple screens showing network telemetry and a "Forensic Analysis Underway" notice, realistic lighting and diverse staff focusing on monitors. Caption: "UMMC incident response and forensic analysis in progress."

2) A state capitol hearing room with city and health officials testifying, microphones and reporters in foreground, a banner reading "State Auditor Inquiry" in the background, documentary photo style. Caption: "Lawmakers press for details after cyberattacks."

KP

About Kishan Prajapat

Kishan Prajapat is the founder of IPDekho and an expert in IP intelligence, geolocation APIs, and website security diagnostics with over 6 years of experience helping businesses block fraud and secure local servers.

Share this article: