Skip to content
The Cyber Security Place

Ransomware against data nobody will buy

Event dated 12 March 2026 · Published 2 September 2026 · 3 sources

A ransomware attack in March 2026 reached the research systems of the University of Hawaiʻi, with an unauthorised user both encrypting and exfiltrating data that included personal information. The case is worth reading because it sits at the edge of how extortion now works. The industry moved from encryption toward publication because publication needs no decryption key and defeats backups. But research data has no resale market and its publication humiliates nobody, so neither lever applies. What remains is the oldest one: work that took years to produce and cannot be reproduced from a receipt.

The economics of extortion have been moving in one direction for three years. Encrypting files stopped working well because organisations learned to restore them, so the pressure shifted to threatening publication — which no backup defeats, and which converts a technical problem into a regulatory and reputational one.

That model assumes the data is worth something to somebody: customers who will be angry, regulators who will fine, competitors who would like a look. A university research environment fails all three tests. The findings are frequently destined for publication anyway, there is no customer list to leak, and the fine, if any, follows from the personal data attached rather than from the research itself.

The leverage that survives

Irreplaceability. A retailer that loses a week of transactions can reconstruct most of it from card processors, suppliers and receipts, because the same events left traces elsewhere. A multi-year dataset of observations exists in exactly one place, and the conditions that produced it — a field season, a cohort, a run of instrument time — cannot be repeated by spending money.

Which makes the calculation for the victim unusually stark and unusually independent of the extortion trend. The question is not whether publication would be damaging. It is whether the only copy is the one now encrypted.

Why universities keep appearing on these lists

Not weak staff and not thin budgets, or not principally. A university runs an estate designed for openness across thousands of semi-autonomous projects, each with its own equipment, its own collaborators, and often its own storage arrangements chosen by a researcher rather than an administrator.

That structure is not an accident to be corrected. It is what makes the institution work — and it means the central team frequently cannot answer where a given dataset lives, let alone whether it is backed up somewhere the same intrusion cannot reach.

The one control that changes the answer

An offline copy of the irreplaceable material, held where an account compromise cannot delete it. Not the whole estate — the subset that could not be regenerated, which is usually far smaller than it first appears and can be identified by asking each group one question: what here could you not produce again if the building burned down?

The answers are worth having written down before anybody needs them, because that list is the difference between an expensive fortnight and a decade of somebody's work being genuinely gone.