Were you recently affected by a data breach?

Mankato Clinic Data Breach

Mankato Clinic, a Minnesota healthcare provider, may have suffered a data breach after hacker group Chaos claimed on September 10, 2026 to have stolen 610 gigabytes of data. The clinic has not confirmed the incident.

Mankato Clinic
Date of Breach: September 10, 2026 (reported, unconfirmed by the company)
CAU logo

Who was affected:

Clients of Mankato Clinic

Impacted Data:

Not yet publicly disclosed

Mankato Clinic, a multispecialty healthcare provider with locations across southern Minnesota, is at the center of reports of a possible data breach. The reports originated from a dark web posting rather than a formal breach notification, and Mankato Clinic has not yet publicly confirmed or detailed an incident. Healthcare organizations handle some of the most sensitive personal and medical information that exists, and when that information may have been compromised, patients and staff deserve a clear, timely accounting of what happened and what is being done to protect them.

Mankato Clinic’s Data Breach Investigation

On September 10, 2026, the hacker group Chaos posted a listing on its dark web leak site claiming to have exfiltrated approximately 610 gigabytes of data from Mankato Clinic, with the attack estimated to have occurred that same day. Cybersecurity monitoring outlets that track ransomware leak sites, including Ransomware.live and RedPacket Security, independently reported the claim shortly after it appeared. As of this writing, Mankato Clinic has not issued a public statement confirming a breach, and no information has been released describing exactly what categories of data, if any, were accessed or how many individuals might be affected.

Claims posted to a ransomware group’s leak site are not, by themselves, proof that a breach occurred or that any particular category of data was taken. Groups operating under a double-extortion model publicize alleged victims to pressure them into paying a ransom, and the claims can sometimes be exaggerated, mistaken, or entirely unconfirmed by the named organization. At the same time, a claim of this kind is often the first public signal of an incident that a company later confirms through a formal notification once its internal investigation concludes. Attorneys investigating potential claims on behalf of Mankato Clinic patients and staff are treating the report as the starting point of an inquiry, not as a final determination of what happened.

Healthcare providers have consistently been among the most frequently targeted sectors for ransomware and data-theft attacks in recent years. The combination of large volumes of sensitive personal and medical records, complex IT environments spanning multiple clinics and specialties, and the operational pressure to restore systems quickly makes hospitals and clinics an attractive target for cybercriminal groups. Industry reporting has repeatedly found that healthcare data breaches are among the most costly to remediate, both because of the sensitivity of the records involved and the regulatory notification obligations that follow.

When a healthcare organization does confirm a breach, state and federal law generally require notification to affected individuals within a defined window once the scope of the incident is understood, along with reporting to relevant regulators such as a state Attorney General’s office and, for breaches involving protected health information, the U.S. Department of Health and Human Services. Investigations into the scope of a ransomware incident, including confirming exactly which files or systems were accessed, can take weeks or months to complete, which is why a delay between an initial leak-site claim and a formal notification letter to patients is common rather than unusual.

If Mankato Clinic’s data was in fact compromised, the type of information typically held by a multispecialty clinic can include names, dates of birth, Social Security numbers, insurance information, and medical record details such as diagnoses and treatment history. Exposure of this kind of information can expose affected individuals to a heightened risk of identity theft, medical identity fraud, and targeted phishing attempts that reference real personal or health details to appear more convincing. Attorneys are gathering information now so that, if a breach is confirmed and the scope becomes clear, affected individuals are positioned to pursue any available legal remedies without delay.

When Did This Breach Occur?

Chaos’s leak-site posting estimated the attack date as September 10, 2026, the same date the listing appeared publicly. Mankato Clinic has not confirmed this date, disclosed when it first detected any unauthorized activity on its network, or indicated when it might notify affected individuals if a breach is ultimately confirmed. This page will be updated if the clinic issues a formal statement or notification with more specific dates.

What Information Was Breached?

The specific categories of information involved, if any, have not been publicly disclosed. Chaos’s claim referenced a volume of data, approximately 610 gigabytes, but did not specify what types of records were included. Multispecialty clinics like Mankato Clinic typically maintain patient names, contact information, dates of birth, insurance details, and medical records, but until Mankato Clinic or a regulator confirms what was actually accessed, the exact scope remains unknown. This page will be updated as more information becomes available.

What You Can Do

If you are a current or former Mankato Clinic patient or employee, there are steps you can take now while more information becomes available:

  • Watch your financial accounts and insurance statements for unfamiliar activity.
  • Be cautious of unexpected calls, emails, or texts referencing Mankato Clinic or claiming to be from the clinic or its billing partners.
  • Consider placing a fraud alert or credit freeze with the major credit bureaus if you receive a formal breach notification.
  • Keep any notification letter or communication from Mankato Clinic, as it may be relevant to a future legal claim.

File a Data Breach Lawsuit Against Mankato Clinic

If you believe your personal or medical information may have been exposed in connection with this reported incident, you may have legal options. Attorneys are currently investigating whether a class action lawsuit can be filed on behalf of affected Mankato Clinic patients and staff, and are looking to speak with anyone who believes their information was put at risk.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: September 10, 2026 (reported, unconfirmed by the company)
Date of Breach: Disclosed on a ransomware group's leak site on September 10, 2026
Date of Breach: Reported to Vermont AGO on September 10, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.