Ransomware Took Down a Hospital's Doors and HVAC

๐ Table of Contents
On August 11, 2026, one of Canada's largest healthcare facilities confirmed it had been hit by ransomware โ and the attack didn't touch a single patient record. Instead, it took down the building itself.
Health Sciences Centre Winnipeg, the biggest hospital in Manitoba, disclosed that a ransomware attack disrupted its facility maintenance systems, including HVAC (heating, ventilation and air conditioning), electronic door access and elevators. The hospital said patient care and clinical services were not affected and that it was investigating the incident. But security experts say the attack is a warning shot: ransomware has moved from the server room into the walls of the building.
What actually happened
HSC Winnipeg is a major teaching hospital and part of Shared Health, Manitoba's provincial health authority. In a statement, the hospital said "certain facility maintenance systems" were affected โ specifically the building management systems (BMS) that control doors, elevators, ventilation and air conditioning.
The hospital was careful to say clinical systems kept running, and patient care was not disrupted. But that distinction is exactly what makes the attack significant. Ransomware operators historically target patient data, billing systems and clinical applications because those are what hospitals pay to recover. This attack went after a different layer entirely: the operational technology (OT) that keeps a hospital physically habitable.
Cybersecurity firm Nozomi Networks, which specializes in OT security, published an analysis of the incident titled "When Ransomware Turns Off the HVAC," noting that unmonitored facility management systems pose a real risk to patient care. In a hospital, ventilation isn't comfort infrastructure โ it is infection control. Electronic door access isn't convenience โ it is physical security for patients, staff and controlled areas.
Why hospitals are a growing target
The Winnipeg attack did not happen in a vacuum. Healthcare ransomware has been escalating all year:
- Researchers recorded 410 healthcare ransomware attacks in the first half of 2026, of which 247 hit hospitals, clinics and other direct care providers and 163 struck supply-chain businesses serving the sector, according to Comparitech data reported by Industrial Cyber.
- The American Hospital Association has described ransomware on hospitals as "threat-to-life crimes" rather than white-collar crime.
- The 2024 Change Healthcare breach โ which the U.S. Department of Health and Human Services says affected about 192.7 million individuals โ remains the largest healthcare data breach in U.S. history and reshaped how the sector thinks about single points of failure.
What is new in 2026 is the target selection. Building management systems are attractive to attackers for several reasons: they are often connected to IT networks for remote monitoring, they are rarely monitored by security teams the way clinical systems are, and they can cause visible, disruptive damage without requiring data exfiltration at all. In some recent incidents, attackers have used building systems as a pressure lever alongside data theft.
What hospitals should do differently
The Winnipeg response โ clinical systems unaffected โ suggests some things went right: the hospital's IT and clinical networks appear to have been isolated from the facility systems that were hit, or the attackers simply didn't reach them. But the incident still offers clear lessons for hospitals everywhere:
- Segment IT from OT. Building management systems should not share a network with clinical or administrative IT. If the BMS is compromised, it should not be able to touch patient systems โ and vice versa.
- Monitor building networks. If nobody is watching the HVAC network, an attacker can move through it for weeks undetected. Anomaly detection on facility systems is cheap relative to a shutdown.
- Plan for physical failure. Hospitals need manual fallbacks for door access, elevators and ventilation control, plus tested procedures for running a building when its automation is offline.
- Test incident response against building scenarios. Most tabletop exercises simulate ransomware on the EHR. Running one where the elevators and HVAC are down instead is a different muscle.
- Assume attackers will escalate. If data theft was the old playbook, physical disruption is the new one. Ransomware gangs are watching which attacks generate the most pressure โ and hospital buildings are a proven lever.
What to watch next
Several questions remain open in Winnipeg: whether any data was exfiltrated (the hospital has not said), how long full recovery of the facility systems takes, and whether the attack group will claim credit. The incident is also likely to prompt reviews at other Canadian health networks with similar building automation setups.
For the rest of us, the lesson is simple. When ransomware hits a hospital, we tend to imagine stolen records and dark screens. In 2026, it can just as easily mean locked doors, dead elevators and a ventilation system that no longer responds โ a reminder that the buildings we rely on are now part of the attack surface.