I Need IT Support Now
Managed Service Provider - Cybersecurity
Shane

MathWorks Ransomware Attack: When Critical Scientific Infrastructure Becomes the Target

MathWorks Confirms Ransomware Incident Affecting MATLAB and Related Services

Ransomware
One Ransomware Attack Froze the Software Behind Research at 6,500 Universities. No Company Is "Too Technical" to Be a Target.

The MathWorks attack disrupted 5 million MATLAB users worldwide. Here is what happened, why it hit so hard, and a checklist to protect your business.

TL;DR
On May 18, 2025, MathWorks - the maker of MATLAB and Simulink - was hit by ransomware that knocked out licensing, downloads, accounts, and cloud services for more than 5 million users worldwide, including 6,500 colleges and universities. Automotive, aerospace, biomedical, and academic teams lost access to core computational tools for over a week. Early analysis pointed to a mix of phishing and unpatched third-party software. MathWorks brought in CrowdStrike and Mandiant, restored multi-factor authentication within days, and moved to a zero-trust architecture. The lesson for every business is not the specific attacker - it is that offline-tested backups, patching (including third-party software), phishing training, and network segmentation are what keep a ransomware hit from becoming a shutdown.

A single ransomware attack on MathWorks disrupted MATLAB and Simulink for more than 5 million users - proof that even highly technical, well-resourced companies get hit.

MATLAB is not a consumer app; it is core infrastructure for engineering, science, and industry. When it went dark, research projects stalled and engineering workflows stopped across the automotive, aerospace, and biomedical sectors. That is exactly why this incident is worth studying: it shows how far the blast radius reaches, and it points straight at the controls every business should already have in place.

The takeaway up front: you cannot guarantee you will never be hit. You can guarantee that a hit does not become a week of downtime - with backups, patching, and segmentation done ahead of time.

What Happened

A Sunday attack that cascaded across MathWorks' entire platform.

Beginning May 18, 2025, ransomware took down MathWorks' licensing, downloads, online store, accounts, and internal systems - and full recovery took more than a week.

The attack hit customer-facing applications and internal IT at once, a pattern that suggests it spread laterally through the network before encrypting. MathWorks first described "multiple applications" having problems, then confirmed ransomware about a week later. Early forensics pointed to a combination of phishing and unpatched vulnerabilities in third-party software. No ransomware group publicly claimed the attack - which can indicate a company paid or is negotiating - and investigators reportedly linked the operators' wallets to payments from other large victims in prior attacks. MathWorks notified federal law enforcement, brought in CrowdStrike and Mandiant, restored multi-factor authentication and single sign-on within days, deployed a temporary offline licensing option, and moved toward a zero-trust architecture.

MATHWORKS INCIDENT TIMELINE MAY 18 Attack begins services go down MAY 21 MFA / SSO restored gradual recovery starts WEEK+ CrowdStrike + Mandiant move to zero trust
The MathWorks ransomware timeline, May 2025.

Why It Hit So Hard - and Who Is at Risk

When one platform is critical to thousands of organizations, one attack stops them all.

The blast radius was huge because so many organizations depend on a single platform - a risk that applies well beyond MathWorks.

  • Academic institutions. Universities and research facilities that run on computational platforms saw research effectively halt when the service went down.
  • Engineering and manufacturing. Teams using MATLAB for control-system design, simulation, and testing - especially automotive and aerospace - lost workflows immediately.
  • Software-as-a-service providers. An attack on one provider's infrastructure can hit thousands of downstream customers at once.
  • Complex software supply chains. The apparent third-party software weakness is a risk for any business integrating many tools without full security oversight.

The pattern is the point: dependence on shared platforms and third-party components concentrates risk. When one link fails, everyone connected to it feels it.

Your Ransomware-Readiness Checklist

The controls that turn a ransomware hit into a bad day, not a shutdown.

These are the same measures the MathWorks recovery leaned on - put them in place before you need them.

  • Offline, tested backups. Keep backups stored offline and restore-test them regularly, so you never have to pay to get your data back.
  • Endpoint detection and response. Deploy EDR that can spot ransomware behavior and suspicious activity before encryption starts.
  • Patch everything - including third-party software. Run regular vulnerability assessments across all components and integrations, not just your own apps.
  • An incident response plan with comms. Document how you will contain, recover, and notify customers - and test it.
  • Phishing training. Teach staff to recognize the social engineering that starts many ransomware attacks.
  • Network segmentation. Limit how far an attacker can move, so one compromised system does not become your whole network.
  • A path toward zero trust. Verify every access request rather than trusting anything inside the perimeter by default.

Would a Ransomware Hit Mean a Week of Downtime?

CinchOps builds the backups, EDR, patching, and segmentation that let a business recover from ransomware fast - and refuse to pay. Find out where your gaps are.

Talk to CinchOps
100% Free

Free Cybersecurity Assessment

Could your business recover from a ransomware attack without paying? Get a FREE assessment of your backups, patching, and response readiness.

Get Your Free Assessment

MathWorks is a deeply technical company with serious resources, and ransomware still put it down for a week. That is the lesson: being smart or specialized does not make you safe. Backups, patching, and segmentation done in advance are what decide whether an attack is a headline or a shutdown.
Shane Stevens, CEO, CinchOps - LinkedIn

Ransomware Defense Built to Recover Fast

CinchOps layers 24/7 monitoring, offline backups, vulnerability management, and network segmentation so a ransomware attack cannot take your business offline - as part of everyday cybersecurity and managed IT.

Explore CinchOps cybersecurity →

How CinchOps Helps Secure Your Business

CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, built to prevent ransomware and recover fast when prevention is not enough.

  • Threat detection and response. 24/7 monitoring that flags ransomware behavior before encryption begins.
  • Vulnerability management. Regular assessments across your software and third-party integrations, the gaps attackers exploit.
  • Backup and recovery. Offline, tested backups so you can restore quickly and never need to pay a ransom.
  • Segmentation and zero trust. Architecture that limits how far an attack can spread.
  • Training and incident response. Awareness training plus tested response plans to minimize downtime.

Do not wait for an attack to find your gaps. Contact CinchOps for a ransomware-readiness assessment.

Frequently Asked Questions

What was the MathWorks ransomware attack?

On May 18, 2025, MathWorks - the maker of MATLAB and Simulink - was hit by ransomware that disrupted licensing, downloads, accounts, the online store, and internal systems. It affected more than 5 million users worldwide, including 6,500 colleges and universities, and full recovery took over a week.

How did the attackers get in?

Early forensic analysis pointed to a combination of phishing and unpatched vulnerabilities in third-party software integrated into MathWorks' systems. The ransomware then spread laterally, encrypting both customer-facing and internal infrastructure.

Did MathWorks pay the ransom?

It has not been confirmed. No ransomware group publicly claimed the attack, which can indicate the victim paid or is negotiating. MathWorks notified federal law enforcement and worked with CrowdStrike and Mandiant on recovery.

What can businesses learn from the MathWorks attack?

That even highly technical, well-resourced companies get hit - and that preparation decides the outcome. Offline-tested backups, patching (including third-party software), endpoint detection, phishing training, network segmentation, and a tested incident response plan are what keep an attack from becoming a shutdown.

How can a small business protect against ransomware?

Focus on the fundamentals: keep offline, tested backups; patch all software including integrations; deploy endpoint detection; train staff on phishing; segment your network; and have a tested incident response plan. A managed IT and security partner can implement and maintain all of these.

Discover More

Sources

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

281-269-6506