Ransomware has moved from a nuisance for small offices to a force that stops fuel, food, hospitals and entire city halls. Each attack below forced a real organisation to halt work, pay out or rebuild from scratch. Here are eleven of the most disruptive cases, from a pipeline operator to a Hawaii campus.
1. Colonial Pipeline: Fuel Line Shut Within Hours

Hit on May 7, 2021, the fuel pipeline operator paid a $4.4 million ransom within hours of the attack, and roughly $2.3 million of it was later seized by authorities. The company halted operations as a precaution while its billing systems were compromised.
The episode showed that a business-network intrusion can stop physical infrastructure even when control systems are untouched. Panic buying and station outages followed across the southeastern United States, long before the pipeline returned to full flow.
2. Kronos (UKG): Payroll Provider Hit in December

Ultimate Kronos Group, known as UKG, was struck in December 2021 in an attack that caused paycheck delays and errors for its clients. The disruption landed on payroll, one of the most closely watched functions in any workplace.
The episode ended in a $6 million settlement. Its place on this list reflects how a single supplier’s outage can spread to the many organisations that depend on it, and how the cost of such an event can continue long after systems are restored.
3. Ascension: A Billion-Dollar Hospital Outage

The May 2024 attack cost the hospital system a reported $1.3 billion and exposed data on 5.6 million people. Clinicians fell back to paper charts, and ambulances were diverted from some emergency rooms.
Patient safety became the central harm, with delayed procedures and disrupted medication ordering across many states. The sheer scale of cost and exposure places the incident among the most damaging healthcare breaches on record. Recovery stretched over weeks, and the financial toll was reported in the billions of dollars.
4. Prospect Medical Holdings: Sixteen Hospitals Under Attack

In August 2023, an attack on Prospect Medical Holdings hit a group of 16 hospitals and 165 clinics, and the attackers made a 50BTC ransom demand. The operator’s footprint meant one intrusion reached a very large number of care sites at once.
A demand set in bitcoin rather than dollars is typical of ransomware cases, and the size of the network made this one stand out. Hospitals and clinics sharing one owner also shared the exposure, which is why the incident earns a place among the year’s most serious healthcare attacks.
5. MGM Resorts: Slot Floors Go Dark

The September 2023 attack on the casino operator brought $100 million in losses in losses, and the company refused to pay. Digital room keys, slot machines and reservation systems failed across its Las Vegas properties.
Staff reverted to handwritten procedures while guests queued at front desks for days. The group’s social-engineering entry point, a phone call to a help desk, became a textbook warning about identity checks. Executives later described the recovery as a long, expensive effort that reached well beyond the gaming floor.
6. Dish Network: Satellite TV Goes Silent

The February 2023 attack caused network outages at the satellite television provider and hit data on more than 290,000 people. Customer service lines and its website went down for days.
The company eventually confirmed that personal information had been taken, and the disruption also unsettled an already shaky merger. A broadcaster whose service depends on constant connectivity found out how little slack it had. Customers who depend on a steady connection tend to notice an outage first, and complaints quickly reached regulators.
7. Western Digital: My Cloud Goes Offline

The March 2023 attack knocked customer services including My Cloud offline for roughly two weeks. The storage maker disclosed that an unauthorised party had gained access to a number of its systems.
Users could not reach files held on its consumer cloud devices, and the company later detailed the theft of customer information. A hardware vendor became a case study in how a single breach can strand the data of ordinary households.
8. City of Dallas: Courts Closed for Weeks

The Royal gang’s May 2023 attack closed Dallas courts through May 31, and the city approved an $8.5 million recovery budget. Police dispatch and other municipal systems were affected as well.
Residents faced delayed hearings, slow records requests and paused payment portals during the cleanup. The incident remains one of the costliest municipal ransomware cases, and it pushed the city toward a larger cybersecurity overhaul. Officials described the response as a multi-month effort that touched nearly every city department.
9. Caesars Entertainment: Half the Demand, Still Millions

The casino group paid $15 million in September 2023, half of the original $30 million ransom demand. The attack came through a social-engineering call to an outsourced IT support vendor.
The firm disclosed the incident in a regulatory filing and said stolen data included its loyalty-program members. Its decision to pay contrasted sharply with a rival hit by the same crew days later that refused. Investigators linked the intrusion to the same affiliate group that targeted other Las Vegas resorts that month.
10. Boeing: Leak After Refusal

LockBit hit the aerospace giant in November 2023 via the Citrix Bleed flaw and published its data when no ransom was paid. The leak included a large volume of files from the parts and distribution business.
The company said flight safety was not affected, and the incident touched only its parts division. It showed how an unpatched edge device can open a path into one of the largest defence and aviation contractors.
11. University of Hawaii: Campus Data Taken

In July 2023 attackers stole 65GB of data, including personal information of 28,000 people, and the university paid the ransom. The attack disrupted systems across the flagship campus and its community colleges.
The payment was controversial among faculty and security experts, who worried it would invite repeat attempts. Students, staff and applicants were offered monitoring, and the case is cited as a reminder that public universities are rich, under-defended targets.
More from Morning Overview
- Long use of a common prostate pill is tied to a higher chance of glaucoma
- Ford is recalling 223,472 F-150 pickups because the fuel tank can leak or detach
- Hybrids have 15% fewer problems than gas cars, while EVs and plug-in hybrids have about 80% more, Consumer Reports finds
- Regulators cleared the first U.S. small modular reactor, 4 months early