avalw news
Noah MitchellNoah MitchellVIEW PROFILE →

Ransomware hits doors, elevators and HVAC at Winnipeg's Health Sciences Centre as clinical care continues

tech2026-08-19 · 3 min read · 151 reads

A ransomware attack disclosed on August 10 struck facility-management systems at Health Sciences Centre, Manitoba's largest hospital, disrupting door access, elevators and ventilation while patient care stayed operational. The incident shows how attackers are moving from encrypting data to disruptin

A ransomware attack against Health Sciences Centre (HSC) in Winnipeg, Manitoba's largest hospital, has disrupted a range of facility-management systems while clinical care continued to run. The incident, disclosed on August 10, 2026, affected the systems that control the physical operation of the building rather than the clinical software used to treat patients, an unusual profile for a ransomware event.

According to Shared Health, the provincial authority that operates the hospital, the attack hit facility maintenance systems including door-access controls, elevators and heating, ventilation and air-conditioning (HVAC). Rather than encrypting patient files or clinical databases, the ransomware reached into the operational technology that keeps a large hospital physically functioning day to day.

Crucially, the health authority stressed that patient care was not interrupted. Shared Health stated that clinical services continued uninterrupted and that, based on the investigation conducted to date, there was no indication that patients had been affected. The hospital remained open and operational throughout the disruption to its building systems.

A physical kind of disruption

Hospitals have become frequent ransomware targets, and attacks on building systems raise new risks. (illustrative photo)
Hospitals have become frequent ransomware targets, and attacks on building systems raise new risks. (illustrative photo)

What makes the incident notable is that it targeted operational technology rather than information technology. Most ransomware campaigns lock up data and demand payment for its release, but this attack interfered with the systems that physically run the facility. Security researchers have warned that as IT and operational technology environments become more interconnected in healthcare, attackers gain new ways to cause tangible, real-world disruption.

The loss of door-access control had immediate physical-security consequences. In response, the hospital increased the presence of security and institutional safety officers at its entrances while the door systems remained affected, and the provincial government was notified of the incident. Managing access to a hospital manually, rather than through electronic controls, adds strain during an already tense situation.

The situation drew concern from frontline staff representatives. Darlene Jackson, president of the Manitoba Nurses Union, warned about the risk created by the loss of access control, saying: "It's worrying for staff because if doors are not secure, then you can have individuals just walking into doors without anyone knowing they're in the building." Her comments underline how a technical failure can translate into direct safety concerns.

Response and investigation

Shared Health said it was moving quickly to contain and resolve the incident. In a statement, the authority said that HSC was working diligently to address the situation as safely and securely as possible, while maintaining continuity of patient care and clinical operations. The hospital also engaged external, third-party cybersecurity experts to help investigate and restore the affected systems.

Several key details remained undisclosed as the investigation continued. No ransomware group or threat actor had been publicly identified, and officials had not said whether a ransom was demanded. It was also not yet clear whether any data was accessed or stolen, with the scope of the intrusion still being assessed beyond the facility-maintenance systems that were visibly affected.

A warning already on record

The attack landed against a backdrop of prior warnings. Manitoba's auditor general had recommended in 2024 that Shared Health strengthen its cybersecurity testing and training, cautioning that shortcomings could lead to delays in responding to incidents. That earlier recommendation now reads as a pointed reminder that the risk to the province's health systems had been formally flagged well before this breach.

Hospitals have become frequent targets for ransomware operators, who calculate that the urgency of healthcare makes victims more likely to pay and more vulnerable to pressure. The Winnipeg case adds a further dimension, showing that the damage is no longer limited to stolen records or locked files but can extend to the doors, elevators and climate systems that a hospital relies on to function safely.

As recovery work continues, the focus will be on fully restoring the building systems, determining the true scope of the intrusion, and clarifying whether any sensitive information was exposed. For hospitals across Canada, the incident serves as a stark reminder that securing operational technology and building automation is now as critical as protecting clinical data, and that the line between digital and physical risk has all but disappeared.

Noah Mitchell
WRITTEN BY THE AUTHOR
Noah Mitchell
2026-08-19 · 3 min read · 151 reads
View profile →
VERIFY THIS STORY
ASK AI
MORE FROM Noah Mitchell
Report this articlesupport@avalw.com