Over the past 18 months, ransomware attacks on tribal governments and tribal health organizations have accelerated sharply. At least six confirmed incidents have disrupted government operations, health clinics, casinos, and victim services programs across Indian Country. Here is what is happening, why it matters for your organization, and what you can do about it.
The Rhysida Pattern
The Rhysida ransomware gang alone has hit at least three tribal entities since late 2025. Their method is consistent: compromised VPN credentials and vulnerable public-facing applications. They demand ransom in bitcoin (typically 8-10 BTC, roughly $660,000 to $700,000) and publish stolen data if not paid. The group remains active as of June 2026 with over 280 documented disclosures worldwide.
Recent Incidents
Cheyenne & Arapaho Tribes (Dec 2025). Rhysida ransomware brought down schools and government systems. The tribe’s governor called it a “terrorist attack”. The attackers demanded $660,000 and published data when the tribe refused to pay. Approximately 80% of systems were restored after one month of recovery work.
Sault Ste. Marie Tribe of Chippewa Indians (Feb 2025). A ransomware attack forced the tribe to shut down all five Kewadin Casino locations, health clinics, and tribal government offices simultaneously. Tribal leadership declined to pay the ransom and instead worked with external cyber experts to recover.
Lower Sioux Indian Community (Apr 2025). The attack began on the casino network and spread into the tribe’s health center, pharmacy, and dental facilities – demonstrating how interconnected networks create pathways for attackers to move beyond their initial target.
MACT Health Board (Nov 2025). Rhysida breached the servers of this tribal health organization serving five California counties. Patient Social Security numbers and medical records were leaked online. Clinics lost phone service, prescription ordering, and appointment scheduling for weeks.
The Cost Reality
Average data breach cost for tribal entities now sits at $4.88 million per incident. Organizations with an incident response plan in place saved an average of $2.03 million compared to those without. A single plan document – one of the simplest things a program can do – cuts the financial impact in half.
What This Means for Victim Services Programs
Victim services programs collect some of the most sensitive data there is: addresses, domestic violence history, child abuse records, and medical information. Yet most rural tribal programs operate with limited or no cybersecurity controls. A ransomware attack on the tribal network can expose the data of every victim a program has ever served.
If your victim services program shares a network with a tribal office, casino, or health clinic – and most do – a breach anywhere on that network puts victim data everywhere on that network.
What You Can Do
The most effective defenses are also the most accessible:
- Turn on MFA. Most breaches start with a stolen password.
- Maintain offline encrypted backups. This is the only reliable defense against ransomware.
- Write a one-page incident response plan. Who do you call? What do you do? When do you contact law enforcement?
- Separate victim data from shared networks. If the casino or admin network goes down, victim data should stay safe.
Every one of these is an allowable use of OVC and VOCA grant funds.
Sources: Tribal Business News, Recorded Future / The Record, Comparitech, Darkfield threat intelligence, REDW Tribal Hospitality & Gaming Webinar (May 2025). Incident window: December 2025 – March 2026.