Threat Intelligence

    Illinois Cybersecurity Breach Report 2025-2026: $535M Lost, 32,977 Complaints

    Jeff SowellAugust 7, 2026
    Illinois Cybersecurity Breach Report 2025-2026: $535M Lost, 32,977 Complaints

    A factual analysis of Illinois cybercrime losses, healthcare and state-agency breaches, school vendor incidents, and the regulatory environment for 2025-2026.

    Published by BlueRadius Cyber | August 2026 | All figures sourced and footnoted

    This report compiles publicly verifiable Illinois-specific data on cybersecurity incidents and regulatory developments from 2024 through mid-2026. Every statistic, date, and named incident is drawn from verified sources only: FBI Internet Crime Complaint Center (IC3) annual reports, official statements from Illinois agencies and affected organizations, HHS Office for Civil Rights filings, Illinois Attorney General guidance, and established reporting. Gang claims are labeled as claims; where no figure has been released, none is invented.

    Executive Summary

    Illinois moved up the national cybercrime rankings in 2025. Residents and organizations filed 32,977 complaints with the FBI IC3, a 29.6% increase over 2024 that lifted Illinois from sixth to fifth place nationally in complaint volume.[1][2][3] Reported losses reached $535,255,201, up from $479,054,271 in 2024.[1][2] Illinois also ranked fifth nationally in ransomware complaints, with 371 filed in 2025.[1]

    Behind the aggregates sits a two-year run of consequential incidents: the Rhysida attack that took Lurie Children's Hospital's electronic health records offline for roughly four months, two Illinois Department of Human Services exposures covering more than 1.8 million records, a vendor breach reaching about 700,000 Chicago Public Schools students, ransomware at the DuPage County courthouse, and federal charges against Chicago ransomware negotiators accused of running attacks themselves. State agencies and third-party vendors are where Illinois data concentrates, and where it keeps leaking.

    Key Findings

    • 32,977 IC3 complaints from Illinois in 2025, fifth highest of any state, up 29.6% from 25,446 in 2024.[1][2][3]
    • $535,255,201 in reported 2025 losses, up from $479,054,271. Illinois ranked eighth in losses, down from fifth, as other states grew faster.[1][2]
    • 371 ransomware complaints in 2025, fifth highest in the country.[1]
    • Illinois residents 60 and older reported $189.49 million in losses across 7,701 complaints in 2025, up from $133.79 million and 6,064 complaints in 2024.[1][2]
    • 791,784 people notified after the January 2024 Rhysida ransomware attack on Lurie Children's Hospital, which kept core EHR systems offline roughly four months.[4][5][6]
    • Two separate IDHS incidents: a 2024 phishing compromise involving 1,118,993 public-assistance customers, and a misconfigured mapping tool that exposed roughly 705,000 people's data from January 2022 to September 2025.[8][9][16][17][18]
    • About 700,000 current and former CPS students had data taken in the late-2024 Cleo vendor breach, one of two school vendor breaches (with PowerSchool) hitting Illinois districts the same winter.[10][11][12]
    • Chicago's DigitalMint case: ransomware negotiators charged with running ALPHV/BlackCat attacks that extorted over $75 million from five organizations; guilty pleas in December 2025.[7]
    • BIPA shifted twice: SB 2979 capped damages at a single violation per person, and on July 13, 2026 the Seventh Circuit vacated the $51.75 million Clearview AI settlement approval.[22][23]

    Bottom line: Illinois is a top-five state for cybercrime and ransomware complaints, and its most damaging incidents flowed through shared infrastructure: state agencies, hospitals, and school vendors. Vendor and identity compromise drove nearly every major loss, and recovery timelines (four months at Lurie, six weeks on paper at Ascension) were the real cost.

    The Headline Numbers: Illinois in the FBI IC3 2025 Annual Report

    The FBI IC3 publishes annual state-by-state data on reported internet crime. The 2025 report places Illinois fifth in complaint volume and eighth in losses; Illinois coverage corroborated the figures.[1][3]

    National Context

    In the 2024 report, Illinois ranked sixth in complaints (25,446) and fifth in losses ($479,054,271).[2] In 2025, complaints jumped 29.6% to 32,977, moving Illinois into fifth place nationally.[1][3] Losses rose to $535,255,201, yet the loss rank slipped from fifth to eighth: loss growth in states above Illinois outpaced even a $56 million year-over-year increase.[1][2] Illinois's 371 ransomware complaints put it fifth nationally.[1]

    Illinois Breakdown

    Within Illinois: complaints rose from 25,446 to 32,977 (+29.6%); losses from $479,054,271 to $535,255,201; 371 ransomware complaints, fifth nationally.[1][2]

    Older residents remain the hardest hit. Illinoisans 60 and older filed 6,064 complaints with $133.79 million in losses in 2024, rising to 7,701 complaints and $189.49 million in 2025.[1][2] That is roughly a 42% one-year increase for the 60-plus cohort, which now accounts for more than a third of the state's reported losses. For Illinois banks, credit unions, healthcare systems, and wealth managers whose customers skew older, customer-targeted fraud is now a first-order risk.

    Major Illinois Breaches and Incidents, 2024-2026

    The incidents below are confirmed by official statements, regulatory filings, or established reporting. They arrive on top of a heavy 2023: Hospital Sisters Health System's August 2023 ransomware attack brought roughly 883,000 notifications and a $7.6 million settlement,[18][19] Cook County Health disclosed 1.2 million patients affected via transcription vendor Perry Johnson & Associates,[4][6] and Monmouth College disclosed a December 2023 incident affecting 44,737 people.[13]

    Lurie Children's Hospital: Four Months of Downtime (January 2024)

    The anchor incident of this period is the ransomware attack on Ann & Robert H. Lurie Children's Hospital of Chicago. Attackers gained access on January 26, 2024, and the hospital took systems offline on January 31.[4][5] The Rhysida gang claimed the attack, demanded 60 bitcoin (roughly $3.4 million at the time), and later claimed it had sold the stolen data; those are the gang's own claims.[4][5][6] The hospital has not said it paid a ransom, and this report makes no such claim.

    What is documented is the operational toll: the electronic health record system and MyChart portal were down roughly four months, with restoration completed May 20, 2024, while clinicians worked on paper. Per the hospital's OCR filing, 791,784 people were notified.[4] For any Illinois healthcare organization modeling ransomware risk, Lurie is the reference case: the dominant cost was not the demand, it was a third of a year without core clinical systems.

    Ascension: Black Basta and Chicago-Area Ambulance Diversions (May 2024)

    Ascension, the multistate health system with hospitals across Illinois, detected a ransomware attack on May 8, 2024, attributed in reporting to Black Basta.[6][20] About 140 hospitals across 19 states ran on paper charting for roughly six weeks, and Chicago-area facilities diverted ambulances.[6][20] In December 2024, Ascension said approximately 5.6 million people were being notified, with a substantial Illinois population in that total.[4]

    IDHS Incident One: The 2024 Phishing Compromise

    On April 25, 2024, a phishing attack compromised Illinois Department of Human Services employee accounts. The agency's official statement puts the scope at 1,118,993 customers whose public-assistance information was accessible, including Social Security numbers of 4,701 customers and 3 employees.[8][9] Public notice came October 31, 2024, roughly six months later.[8]

    IDHS Incident Two: 705,000 Records Exposed by a Mapping Tool (2022-2025)

    The second IDHS incident is arguably worse because no attacker was required. Misconfigured public-facing mapping tools left personal information exposed on the open internet from January 2022 until discovery on September 22, 2025. The exposure covered 672,616 Medicaid and Medicare Savings Program recipients and 32,401 Division of Rehabilitation Services customers, roughly 705,000 people. Public notice did not come until January 2, 2026.[16][17][18]

    Together, the two incidents make this report's systemic point: one agency accounted for more than 1.8 million exposed records, once via phishing and once via a configuration error unnoticed for over three and a half years. Organizations that exchange data with state agencies inherit this exposure.

    Chicago Public Schools via Cleo: 700,000 Students (Late 2024)

    Chicago Public Schools was hit through its vendor Cleo, a file-transfer software company breached in late 2024. Data on roughly 700,000 current and former students, reaching back to the 2017-18 school year, was taken: names, dates of birth, CPS identification numbers, and for some students Medicaid identification numbers. CPS stated no Social Security numbers were involved. Families were notified in March 2025.[11][12]

    PowerSchool: The Second School Vendor Breach of the Same Winter (December 2024)

    Weeks later, the December 28, 2024 breach of PowerSchool, the dominant K-12 student information system, reached Illinois districts including Mundelein High School District 120, New Trier, Lisle, and Elmhurst.[10][5] Two school vendor breaches in one winter established the school supply chain as an Illinois pattern: districts hold sensitive data on minors, but the breaches happened at vendors they do not control.

    DuPage County: Ransomware at the Courthouse Complex (April 2025)

    At about 2:30 a.m. on April 28, 2025, ransomware struck the DuPage County courthouse complex in Wheaton, knocking out systems for the county sheriff's office, the 18th Judicial Circuit Court, and the Circuit Court Clerk. The FBI and U.S. Secret Service were brought in, and courts stayed open while staff worked around downed systems.[14] No gang has been publicly named and no count of affected individuals has been released; this report states neither. It is the largest confirmed ransomware attack on Illinois county government in the period.

    Henry County: Medusa Ransomware Against County Government (March 2024)

    Henry County, in northwestern Illinois, was hit by the Medusa gang on March 18, 2024, with a $500,000 demand and an eight-day deadline. The county's 911 service stayed operational, and the FBI and CISA were engaged.[13] With DuPage a year later, it shows county targeting runs from the Chicago collar to rural downstate.

    Saint Anthony Hospital: A Breach That Grew 20-Fold on Investigation (February 2025)

    Saint Anthony Hospital, on Chicago's West Side, detected an intrusion on February 6, 2025. An initial count of 6,679 people was later revised to 146,108 (Social Security numbers, medical record numbers, prescription information); the hospital said its EMR system was not affected.[4][6][15] The 20-fold revision is a recurring lesson: first counts are floor estimates.

    Illinois HFS: Child-Support Data Phishing (February 2025)

    Smaller but pointed: a phishing compromise at the Illinois Department of Healthcare and Family Services, detected around February 11, 2025, exposed Social Security numbers, identification numbers, and child-support financial information for 933 individuals, 564 of them Illinois residents. Notices went out May 23, 2025.[5]

    Village of Mundelein: A Ten-Month Notification Timeline (2025)

    The Village of Mundelein (distinct from the school district hit via PowerSchool) disclosed that an unauthorized actor had network access from January 13 to February 1, 2025; scope was determined October 17, 2025, and notices went out November 12, 2025.[21] Roughly ten months from intrusion to notification shows how long municipal investigations actually run under the "most expedient time possible" standard.

    The DigitalMint Case: Ransomware Negotiators Charged With Running Attacks

    The most unusual Illinois story of the period is a prosecution, not a breach. Federal charges accused employees of DigitalMint, a Chicago-based ransomware negotiation and crypto payments firm, and an incident-response manager at the security firm Sygnia, of conducting ALPHV/BlackCat attacks while working in the ransomware-response industry. Prosecutors alleged more than $75 million was extorted from five organizations. Guilty pleas followed in December 2025, and roughly $9 million in cryptocurrency was seized.[7] The governance lesson outlasts the novelty: incident-response vendors get privileged access at the worst moment, and crisis-hired firms deserve the same due diligence as any vendor with administrative access.

    The Water Utility Wave That Stopped at the Border

    One negative finding deserves its own section: no verified cyberattack on an Illinois water utility's control systems occurred during this period. An NBC Chicago investigation published August 3, 2026 documented a multi-state wave of attacks on water utilities that reached Michigan, Wisconsin, Minnesota, and Georgia, and found no Illinois attack.[24] The nearest brush was corporate: American Water, parent of Illinois American Water, paused billing in October 2024 after a cyberattack.[25]

    The correct reading is not relief. A campaign that has already hit utilities in neighboring Wisconsin and Michigan is targeting guidance: Illinois water systems, especially small ones without security staff, should treat the NBC Chicago findings as a map of what is coming, segment control systems, require MFA on remote access, and plan for the wave crossing the border.

    The Illinois Regulatory Environment

    Illinois operates two regimes that matter here: a breach notification statute with agency-specific deadlines, and the nation's most litigated biometric privacy law.

    PIPA: The Illinois Personal Information Protection Act

    The Personal Information Protection Act (815 ILCS 530) requires notifying affected Illinois residents "in the most expedient time possible and without unreasonable delay."[22] Its sharper edges are entity-specific: businesses must notify the Illinois Attorney General when a breach affects more than 500 Illinois residents; state agencies face a stricter trigger, more than 250 residents, with notice due within 45 days; and HIPAA-covered entities must copy the Attorney General on any HHS breach notification within five business days.[22] The IDHS mapping and Mundelein timelines show how much room the "most expedient" standard leaves once investigation time is counted.

    BIPA: A Narrowed Statute and a Reopened Landmark Case

    The Biometric Information Privacy Act remains the Illinois law with the largest private-litigation footprint, but its economics changed. SB 2979, signed August 2, 2024, amended BIPA so repeated collection of the same person's biometric data counts as a single violation rather than accruing per scan, overturning the Illinois Supreme Court's Cothron rule, and authorized electronic-signature consent. The Seventh Circuit has confirmed the amendment applies retroactively.[23]

    Two enforcement data points frame current exposure. The $51.75 million Clearview AI class settlement, approved March 20, 2025, was vacated by the Seventh Circuit on July 13, 2026; as of publication, the largest BIPA settlement on record is unwound and the case is back in play.[23] Meanwhile Speedway's $12.1 million fingerprint-timekeeping settlement became final in October 2025, a reminder that ordinary workplace biometrics drive BIPA liability. Employers using fingerprint or face-based timeclocks should treat written policy, consent capture, and retention schedules as compliance basics.

    What This Means for Illinois Mid-Market Organizations

    Three operational implications drop out of the data:

    1. Your vendor list is your attack surface

    The defining Illinois school breaches (Cleo, PowerSchool) happened at vendors, not districts. Cook County Health's 1.2 million-patient exposure came through a transcription vendor. Even the DigitalMint prosecution is, at bottom, a vendor-trust failure. Inventory every vendor holding regulated data or remote access, and move vendor risk from an onboarding questionnaire to continuous review: breach-notification clauses with hard deadlines, evidence of MFA and logging, and a named internal owner. This is the kind of standing program a fractional CISO builds and runs for organizations that cannot justify a full-time security executive.

    2. Identity and configuration failures beat malware

    Two state-agency incidents began with phishing (IDHS 2024, HFS 2025), and the largest by duration required no attacker: a mapping tool misconfigured for over three and a half years. The preventive controls are unglamorous: phishing-resistant MFA on employee accounts, least-privilege access to bulk records, and scheduled configuration review of anything public-facing. Audit your own public surface (portals, map tools, file shares, storage buckets) on a calendar, not after an incident.

    3. Plan for downtime measured in weeks, and price it before the incident

    Lurie Children's ran without its EHR for roughly four months. Ascension charted on paper for about six weeks. DuPage County kept courts open only by working around downed systems. The binding constraint in ransomware is restoration time, so the tests that matter are restoration tests: documented downtime procedures, offline backups actually restored on a schedule, and an incident plan rehearsed with the executives who would live it. A senior leader engaged through virtual CISO services can pressure-test recovery assumptions in weeks and give the board a defensible answer to "how long would we be down."

    For metro-area organizations, this work benefits from local context: the incidents in this report cluster in Cook and the collar counties, across healthcare, public agencies, and schools. BlueRadius provides virtual CISO services in Chicago for organizations that want security leadership familiar with exactly this landscape, from BIPA obligations to the vendor ecosystems Illinois schools, hospitals, and municipalities depend on.

    Frequently Asked Questions

    How much did Illinois lose to cybercrime in 2025?

    $535,255,201 in reported losses across 32,977 complaints, per the FBI IC3 2025 Annual Report. Complaints rose 29.6% over 2024, moving Illinois from sixth to fifth nationally in complaint volume; the state ranked eighth in losses.[1][2]

    What was the biggest Illinois healthcare breach of this period?

    By Illinois-specific impact, the January 2024 Rhysida ransomware attack on Lurie Children's Hospital: 791,784 people notified per its OCR filing, with core EHR systems offline roughly four months, until May 20, 2024.[4][5] The multistate Ascension attack (about 5.6 million notified) also hit Illinois, with ambulance diversions and six weeks of paper charting.[4][6][20]

    What happened at the Illinois Department of Human Services?

    Two separate incidents. An April 25, 2024 phishing compromise made 1,118,993 customers' public-assistance information accessible, including SSNs of 4,701 customers and 3 employees; notice came October 31, 2024.[8][9] Separately, misconfigured mapping tools exposed data on roughly 705,000 people (672,616 Medicaid and Medicare Savings Program recipients, 32,401 rehabilitation-services customers) from January 2022 until discovery September 22, 2025; public notice came January 2, 2026.[16][17][18]

    Were Illinois schools breached?

    Yes, primarily through vendors. The late-2024 Cleo breach exposed data on about 700,000 current and former CPS students back to 2017-18 (no Social Security numbers, per CPS), with families notified March 2025.[11][12] The December 28, 2024 PowerSchool breach reached districts including Mundelein High School District 120, New Trier, Lisle, and Elmhurst.[10]

    Has ransomware hit Illinois local governments?

    Yes. DuPage County's courthouse complex in Wheaton was hit April 28, 2025, taking sheriff, circuit court, and court clerk systems offline; no gang has been publicly named and no victim count released.[14] Henry County was hit by Medusa on March 18, 2024, with a $500,000 demand; 911 stayed up.[13] Illinois filed 371 ransomware complaints with IC3 in 2025, fifth most nationally.[1]

    Is BIPA still a major liability for Illinois businesses?

    Yes, though the shape changed. SB 2979 (August 2, 2024) caps accrual at one violation per person rather than per scan, and the Seventh Circuit confirmed it applies retroactively.[23] But enforcement is active: Speedway's $12.1 million fingerprint-timeclock settlement became final in October 2025, and the $51.75 million Clearview AI settlement approval was vacated by the Seventh Circuit on July 13, 2026, leaving the largest BIPA case unresolved and ongoing.[23]

    Were Illinois water utilities attacked?

    No verified attack on an Illinois water utility occurred in this period. NBC Chicago's August 3, 2026 investigation documented a multi-state wave that reached Michigan, Wisconsin, Minnesota, and Georgia but not Illinois.[24] Illinois utilities should treat that geography as targeting guidance and harden remote access and segmentation now.

    Cite This Report

    Journalists, researchers, and security teams are welcome to cite this report with attribution:

    Source: "Illinois Cybersecurity Breach Report 2025-2026," BlueRadius Cyber, a virtual CISO services firm. https://blueradius.io/illinois-cybersecurity-breach-report-2026

    Media inquiries and data questions go to the BlueRadius contact page.

    Engage a vCISO to Operationalize These Findings

    The Illinois record above (vendor compromise, phishing against privileged accounts, multi-month ransomware recovery, biometric liability) is a leadership problem before it is a tooling problem. Someone accountable has to own vendor risk, identity controls, tested restoration, and the notification clock. BlueRadius's virtual CISO services put a senior security leader inside your organization to turn findings like these into a board-defensible program.

    The fastest way to see where you stand against these patterns is a structured baseline: request a free cybersecurity assessment for a prioritized view of your exposure across identity, vendors, recovery, and Illinois-specific compliance obligations.

    BlueRadius Research Library

    Sources

    [1] FBI Internet Crime Complaint Center, "2025 Internet Crime Report" (Illinois state statistics). ic3.gov

    [2] FBI Internet Crime Complaint Center, "2024 Internet Crime Report" (Illinois state statistics). ic3.gov

    [3] The Center Square, coverage of Illinois figures in the IC3 2025 Annual Report. thecentersquare.com

    [4] HIPAA Journal, coverage of Lurie Children's, Ascension, Saint Anthony Hospital, and Cook County Health / PJ&A. hipaajournal.com

    [5] ABC7 Chicago, reporting on Lurie Children's, PowerSchool districts, and the HFS phishing incident. abc7chicago.com

    [6] Chicago Sun-Times, reporting on Lurie Children's, Ascension, Saint Anthony, the IDHS mapping exposure, and Cook County Health / PJ&A. suntimes.com

    [7] Chicago Sun-Times, The Watchdogs, reporting on the DigitalMint / Sygnia ALPHV-BlackCat prosecutions, March 13, 2026. suntimes.com

    [8] Illinois Department of Human Services, official statement on the April 2024 phishing incident. idhs.prezly.com

    [9] Government Technology, reporting on the IDHS phishing breach. govtech.com

    [10] Daily Herald, reporting on Illinois districts affected by the PowerSchool breach. dailyherald.com

    [11] Chicago Sun-Times, reporting on the CPS / Cleo vendor breach, March 8, 2025. suntimes.com

    [12] Chicago Public Schools, official breach notifications page. cps.edu

    [13] The Record, "Illinois county government, college hit with ransomware" (Henry County / Medusa; Monmouth College). therecord.media

    [14] Government Technology, "Continuity Ensured in DuPage County, Ill., Ransomware Attack." govtech.com

    [15] Saint Anthony Hospital, official cybersecurity incident notice. sahchicago.org

    [16] Capitol News Illinois, reporting on the IDHS mapping-tool exposure. capitolnewsillinois.com

    [17] TechCrunch, reporting on the IDHS mapping-tool exposure and January 2, 2026 notice. techcrunch.com

    [18] BleepingComputer, reporting on the IDHS mapping exposure and the HSHS breach and settlement. bleepingcomputer.com

    [19] Illinois Times, reporting on the Hospital Sisters Health System $7.6 million settlement. illinoistimes.com

    [20] CNN, reporting on the Ascension ransomware attack and Black Basta attribution. cnn.com

    [21] Village of Mundelein, official data incident notice (November 12, 2025). mundelein.org

    [22] Illinois Attorney General, Personal Information Protection Act (815 ILCS 530) breach notification guidance. illinoisattorneygeneral.gov

    [23] Illinois General Assembly, SB 2979 (2024 BIPA amendment); U.S. Court of Appeals for the Seventh Circuit, order vacating approval of the Clearview AI settlement, July 13, 2026. ilga.gov

    [24] NBC Chicago Investigations, reporting on the multi-state water utility attack wave (Michigan, Wisconsin, Minnesota, Georgia; no Illinois attack documented), August 3, 2026. nbcchicago.com

    [25] Illinois Public Media, reporting on American Water (parent of Illinois American Water) pausing billing after an October 2024 cyberattack. ipmnewsroom.org

    All figures and named incidents are drawn from official statements, regulatory filings, or established reporting. Where an official count or attribution has not been released, none is stated.

    Illinoisbreach reportransomwareIC3BIPAhealthcare breachesChicagostate government

    Related from the BlueRadius Library

    Sourced posts on adjacent topics, ranked by tag overlap.

    Threat Intelligence

    Florida Cybersecurity Breach Report 2025-2026: City, County & Statewide Incident Tracker

    A sourced tracker of Florida city and county data breaches and ransomware (2024-2026), plus statewide IC3 losses and healthcare breaches.

    Read

    Compliance

    HIPAA Breach Report 2026: OCR Data, Ransomware Trends, and What Mid-Market Healthcare Must Do Next

    Factual 2024 HIPAA breach analysis: 276 million records exposed, 725 OCR-reported breaches, and Change Healthcare at 190 million. Fully sourced.

    Read

    Threat Intelligence

    Higher Education Cybersecurity Breach Report 2026: 251 Ransomware Attacks, 3.96M Records Breached

    Sourced analysis of higher education cybersecurity: 251 ransomware attacks in 2025, 3.96M records, and the MOVEit cascade across 900 colleges.

    Read

    Threat Intelligence

    CMMC Phase 2 Readiness Checklist: Nov 10, 2026 Deadline + 110 Control Path

    Step-by-step CMMC 2.0 Phase 2 readiness before the November 10, 2026 deadline: all 110 NIST SP 800-171 controls, SSP and POA&M, and C3PAO assessment.

    Read

    Threat Intelligence

    Penetration Testing vs Vulnerability Scanning: What Your Business Actually Needs (2025)

    The key differences between penetration testing and vulnerability scanning, when to use each, and how to build a program that satisfies compliance.

    Read

    Threat Intelligence

    The Executive's Guide to Digital Forensics: Protecting Your Organization Post-Breach

    How digital forensics planning protects enterprise value, reduces liability, and speeds recovery after a cyber incident.

    Read

    Related services

    Related on Radius360

    Take the Next Step

    Ready to Strengthen Your Security Posture?

    BlueRadius Cyber delivers Fortune 500-grade protection for mid-market companies — virtual CISO leadership, 24/7 managed security, and compliance programs that actually close deals. Let's talk.