Mon General Hospital (West Virginia) Notifies Patients After May 2026 Phishing Attack Compromises Employee Email Accounts, Exposing PHI/PII Including Social Security Numbers — Threadlinqs Intelligence
As of 2026-08-01, Mon General Hospital (West Virginia) Notifies Patients After May 2026 Phishing Attack Compromises Employee Email Accounts, Exposing PHI/PII Including Social Security Numbers is a high-severity data breach threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 20 indicators of compromise.
Threat ID: TL-2026-1810 · Severity: HIGH · Status: ACTIVE · Category: DATA_BREACH
Monongalia County General Hospital Company (Mon General, West Virginia) discovered on May 6, 2026 that a phishing attack had compromised a small number of employee email accounts; unauthorized access
On May 6, 2026, Mon General (Monongalia County General Hospital Company), part of Monongalia Health System, Inc. in Morgantown, West Virginia, identified that a phishing attack had targeted and compromised a small number of employee email accounts. The hospital states it terminated unauthorized access to the affected mailboxes the same day it was discovered and engaged an external cybersecurity/forensic firm to investigate, reset user credentials, and evaluate additional technical safeguards. The investigation, which concluded in late June 2026, determined that the compromise was confined to the small number of email accounts identified and did not extend to any other data storage system or hospital IT system (electronic health records were not implicated). Investigators determined the attacker may have been able to view patient first and last names, dates of birth, email addresses, phone numbers, Social Security numbers, and health or health insurance information contained in or attached to the compromised mailboxes. Mon General began mailing notification letters to affected patients around late July/early August 2026, offering two years of complimentary credit monitoring and operating a dedicated toll-free helpline (844-958-8936; WDTV states Mon-Fri 8:00am-5:30pm, WAJR states Mon-Fri 9:00am-6:30pm — hours differ slightly across corroborating outlets) for patient questions. No CVE, malware family, exploit, or specific threat-actor attribution has been disclosed in any public reporting; this is a breach-notification-driven disclosure rather than a technical vulnerability advisory, so exploit-chain and infrastructure detail is limited to what the hospital and corroborating outlets have stated.
Notably, this is not the first email-based compromise at this health system. In a separate, unrelated pair of 2021 incidents, unauthorized individuals accessed a Monongalia Health System contractor's email account between May 10 and August 15, 2021, and used it to send fraudulent wire-transfer requests (T1657 Financial Theft) and conduct further phishing; the intrusion was discovered in late July 2021 (around July 28) only when a vendor reported not receiving an expected payment. Affected organizations named in that 2021 disclosure include Monongalia Health System, Inc., Monongalia County General Hospital Company, and Stonewall Jackson Memorial Hospital Company (two other affiliated facilities, Mon Health Preston Memorial Hospital and Mon Health Marion Neighborhood Hospital, were confirmed NOT involved). That breach exposed PHI/PII — names, addresses, Social Security numbers, Medicare Health Insurance Claim numbers, dates of birth, patient account numbers, health-plan member IDs, medical record numbers, service dates, provider names, and claims/clinical treatment data — for approximately 398,164 patients, and was disclosed to patients beginning December 21, 2021 (reported publicly December 23, 2021). The organization stated it subsequently implemented multi-factor authentication for remote email access as a corrective measure following that incident. The recurrence of an employee-email-account compromise via phishing at the same health system in 2026 — years after MFA was reportedly deployed as a remediation for the 2021 incident — is a notable pattern worth flagging for correlation and defensive tracking, though public reporting on the 2026 incident does not disclose whether MFA was bypassed, not enforced for the affected accounts, or not a factor at all.
The incident sits within a well-documented healthcare-sector threat landscape. HHS's Health Sector Cybersecurity Coordination Center (HC3) has repeatedly warned that phishing and business email compromise (BEC) are among the most common and most financially damaging attack vectors against healthcare organizations: one HC3 sector alert documented over $50.8 billion in BEC losses affecting healthcare between October 2013 and December 2022, with 2023-2024 median per-incident losses near
Target sectors: health
Target regions: North America
Detections & IOCs
As of 2026-08-26, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 20 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
DATA_BREACH, HIGH, threat intelligence, cybersecurity, T1589, T1598, T1583, T1586, T1566, T1539, T1557, T1078, T1078, T1078