Breach report · Healthcare

Health Sciences Centre Ransomware Attack in Winnipeg: What We Know So Far

Health Sciences Centre Winnipeg confirmed a ransomware incident on August 10, 2026 hitting HVAC and door-access systems, with clinical care unaffected.

What happened in the HSC Winnipeg ransomware attack?

Health Sciences Centre reported the ransomware incident during the afternoon of August 10, 2026.

According to HSC, the attack affected a number of facility maintenance systems, specifically including HVAC and door-access systems. Clinical services remained operational at the time of the announcement.

The Winnipeg Free Press reported that a side entrance was closed and visitors were directed toward the hospital’s main doors, although other outdoor entrances appeared to be operating normally. The exact extent of the impact on internal access-control systems was not immediately known.

That makes this incident particularly noteworthy.

Most people associate ransomware with encrypted laptops, inaccessible documents or stolen databases. But modern organizations rely on connected technology for physical operations as well.

Door access. Building controls. HVAC. Security systems. Communications. Manufacturing equipment. Logistics systems.

When those technologies become part of the attack surface, a cyberattack can become a business continuity and physical operations problem, not simply an IT problem.

What systems were affected at Health Sciences Centre?

HSC has publicly identified two categories of affected facility systems:

  • Door-access systems
  • HVAC systems

The hospital has described the broader affected environment as its facility maintenance systems.

There has been no public confirmation that clinical systems, medical devices, electronic health records or patient databases were compromised.

That distinction matters.

Health Sciences Centre is Manitoba’s largest healthcare facility. The campus spans approximately 39 acres and more than four million square feet, with more than 8,000 staff, physicians and volunteers. It provides specialized services including trauma, transplant, burn, neurosciences, cancer and pediatric care, and serves patients from Manitoba as well as parts of Northwestern Ontario and Nunavut.

A disruption involving physical infrastructure at a facility of that scale illustrates why cybersecurity and operational resilience are increasingly interconnected.

Was patient information stolen in the HSC ransomware attack?

There is currently no public confirmation that patient information was stolen.

This is why the incident should not yet be described as a confirmed patient-data breach.

HSC has said that based on its investigation so far, there is no indication patients have been affected and clinical services continue uninterrupted.

Ransomware groups frequently attempt data theft in addition to encryption, but it would be speculation to say that happened in this case without confirmation from HSC, Shared Health or investigators.

The situation may change as forensic work continues.

What don’t we know yet?

As of August 10, 2026, several critical details have not been made public:

The ransomware group: No threat actor has been publicly identified.

The initial point of entry: There is no confirmed information about how attackers gained access.

Whether data was stolen: No confirmed exfiltration of patient, employee or organizational data has been announced.

The ransom demand: HSC has not publicly disclosed whether a ransom was demanded or its amount.

The full scope of affected systems: Facility maintenance systems are known to be affected, but the complete technical scope has not been released.

Recovery timeline: No definitive timeline for full restoration has been announced.

These unknowns are important. Cyber incident investigations can take time, and early information frequently changes as forensic teams determine what happened.

Why the HSC ransomware attack matters beyond healthcare

The most important cybersecurity lesson from the information available so far is not simply that another Canadian healthcare organization experienced ransomware.

It is what was affected.

HVAC and electronic door-access systems interact with the physical environment.

For hospitals, manufacturers, warehouses, construction companies, professional offices and other organizations, connected building and operational technologies can create an additional layer of cyber risk.

An organization can have protected cloud applications and secured laptops while still overlooking systems such as:

  • building management systems
  • electronic access controls
  • security infrastructure
  • connected sensors
  • legacy servers
  • specialized operational equipment
  • vendor-managed devices
  • network-connected appliances

The HSC incident does not prove how its network was structured or how the attackers reached the affected systems. But the reported impact demonstrates why organizations need visibility beyond traditional desktops and servers.

Cybersecurity inventories need to answer a basic question:

What is connected to our environment, and what happens to our operations if we lose control of it?

Manitoba’s Auditor General had previously reviewed Shared Health’s cyber incident preparedness

There is another important piece of context.

In December 2024, Manitoba’s Auditor General released an audit specifically examining the Cybersecurity Incident Response Process at Shared Health.

The audit found that Shared Health had established a cybersecurity incident response plan and had external cybersecurity resources available, but identified several areas requiring improvement.

Among the findings at that time were that cybersecurity response exercises had not been performed to test the plan, dedicated training had not been conducted with the entire response team, an external communications plan remained incomplete, and additional ransomware and extortion procedures were still being developed.

The Auditor General issued four recommendations focused on strengthening the organization’s incident-response preparedness.

It is important not to draw a causal connection between those 2024 findings and the ransomware incident occurring in 2026. Shared Health may have implemented improvements since the audit, and the technical cause of the current incident has not been disclosed.

But the audit reinforces a broader cybersecurity lesson:

Having an incident response plan is not the same as knowing that the plan will work during a real attack.

Plans need to be practised.

Ransomware remains a major threat to Canadian critical infrastructure

The Canadian Centre for Cyber Security has identified ransomware as one of the most significant cybercrime threats facing Canada’s critical infrastructure.

Its National Cyber Threat Assessment warns that ransomware can directly disrupt critical services and potentially affect the wellbeing of Canadians.

Healthcare has already experienced significant Canadian ransomware incidents.

The Cyber Centre highlights the 2022 attack involving Toronto’s Hospital for Sick Children and the 2023 cyberattack that disrupted five hospitals in Southwestern Ontario through a shared IT provider. The Ontario attack resulted in internal system outages, theft of sensitive files and delays to patient care.

The HSC incident adds another example of how ransomware continues to create operational risk for Canadian organizations.

And that risk is not limited to hospitals.

What can Canadian businesses learn from the HSC ransomware incident?

Organizations do not need to know exactly how the HSC attack occurred to examine their own ransomware preparedness.

A useful starting point is to ask what would happen if ransomware entered your environment tonight.

Would somebody notice?

How quickly could the affected device or account be isolated?

Could an attacker move from regular business systems into critical infrastructure?

Could the organization continue operating without its primary systems?

Could backups actually be restored?

Would everyone know what to do?

Strong ransomware defence requires several layers working together.

1. Know everything connected to your network

You cannot protect systems you do not know exist.

Organizations should maintain an accurate inventory of endpoints, servers, cloud systems, networking equipment and connected operational technology.

Older and vendor-managed systems deserve particular attention.

2. Use endpoint detection and 24/7 security monitoring

Traditional antivirus alone is not enough to provide visibility into modern attacks.

Endpoint Detection and Response (EDR), centralized security monitoring and rapid incident triage can help identify suspicious behaviour before an attacker has time to move throughout an environment.

Organizations without their own security operations team can use a managed security service to provide continuous monitoring, detection and incident-response capabilities.

happier IT’s managed security services include 24/7 security operations, endpoint detection and response, vulnerability management, patch management, network security and other defensive controls for organizations in Alberta and British Columbia.

3. Protect identities with MFA and least privilege

Compromised credentials remain an important security risk.

Multi-factor authentication should protect important accounts, especially administrative, remote-access, email and cloud accounts.

Access should also follow the principle of least privilege so a compromised account cannot automatically reach every system.

The Canadian Centre for Cyber Security includes MFA and access controls among recommended ransomware protections.

4. Segment critical systems

Business computers should not automatically have unrestricted access to every critical operational system.

Network segmentation can help create boundaries between user devices, servers, guest networks, administrative systems and operational technology.

Segmentation does not make ransomware impossible, but it can reduce an attacker’s ability to move laterally through the organization.

5. Patch vulnerabilities before attackers exploit them

Operating systems, applications, networking equipment and internet-facing infrastructure need an active vulnerability and patch-management process.

That means identifying vulnerabilities, prioritizing them according to risk and confirming that fixes were actually deployed.

The Cyber Centre specifically recommends timely operating-system and application patching as a core ransomware defence.

6. Maintain backups ransomware cannot destroy

A backup that ransomware can encrypt along with the production environment is not a reliable recovery strategy.

The Canadian Centre for Cyber Security recommends encrypted backups that are stored offline or otherwise disconnected from production networks, along with regularly testing those backups to ensure they can actually restore operations.

Recovery needs to be tested before an emergency.

7. Practise the incident response plan

Organizations should know in advance:

Who makes the decisions?

Who isolates systems?

Who contacts the cybersecurity team?

Who communicates with employees and customers?

Who contacts insurers, legal counsel and appropriate authorities?

Which operations must be restored first?

A tabletop exercise can expose weaknesses that are difficult to see in a document.

The Cyber Centre’s ransomware guidance specifically covers preparation, immediate response, recovery and post-incident improvement.

8. Include suppliers and third parties in cybersecurity planning

Most businesses depend on external technology providers, cloud platforms and software vendors.

Those relationships create dependencies.

Organizations should understand what systems third parties can access, how that access is authenticated, what happens when a provider is compromised and how access can be quickly revoked during an incident.

Ransomware doesn’t have to encrypt your entire company to disrupt it

That may ultimately be one of the most important lessons from what has been reported at Health Sciences Centre.

A cyberattack does not necessarily need to shut down every computer in an organization to create a serious operational problem.

A compromised identity system can disrupt employee access.

A compromised firewall can affect connectivity.

A compromised building-control system can affect physical operations.

A compromised server can interrupt an essential application.

The objective of modern cybersecurity therefore isn’t simply to “stop viruses.”

It is to make an organization difficult to compromise, quick to detect, difficult to move through and capable of recovering when something gets through.

Frequently Asked Questions

Did Health Sciences Centre Winnipeg suffer a ransomware attack?

Yes. Health Sciences Centre confirmed a ransomware incident on August 10, 2026 affecting facility maintenance systems, including HVAC and door-access systems.

Is Health Sciences Centre still open after the ransomware attack?

Yes. HSC said clinical services were continuing uninterrupted and advised patients who need care to continue attending the hospital.

Was patient information stolen in the HSC ransomware attack?

There is currently no public confirmation that patient information was stolen. HSC said its investigation had found no indication at that point that patients were affected.

What systems were affected by ransomware at HSC Winnipeg?

HSC has confirmed that facility maintenance systems were affected, including HVAC and door-access systems. The full technical scope has not yet been publicly released.

Who attacked Health Sciences Centre Winnipeg?

No ransomware group or threat actor has been publicly identified as responsible as of August 10, 2026.

Did HSC pay a ransomware demand?

There is currently no public information confirming whether a ransom was demanded, how much may have been requested or whether any payment was made.

How can businesses protect themselves from ransomware?

Organizations should use layered security including MFA, endpoint detection and response, security monitoring, vulnerability and patch management, network segmentation, protected backups and a tested incident-response plan. Canada’s Cyber Centre recommends many of these controls as part of ransomware prevention and recovery.

More from the feed

Other incidents we've written up.

Want to know what this would look like for you?

A 30-minute call. No slides, no audit fee, no obligation. We ask what is breaking and tell you honestly whether we are the right fit.