LIVE · cybersecurity feed
Live wire
breach

CareCloud Breach Exposes Medical and Financial Data of 345,000

CareCloud disclosed a breach affecting 345,000 people after hackers stole medical and financial data from its AWS-hosted systems. TechCrunch reports that CareCloud, the New Jersey-based health tech company that stores patient records for more than 45,000 providers across the US, is finally notifying people impacted by a breach the firm first disclosed back in March. […]

zeroday.news · 2h ago

CareCloud, a New Jersey-based health technology company, has confirmed a data breach affecting approximately 345,000 individuals, with the number potentially increasing as more state filings are processed. The incident involved unauthorized access to one of the company's electronic health record (EHR) data stores hosted on Amazon Web Services (AWS).

The breach occurred between March 10 and March 16, 2026, during which an unauthorized third party accessed a CareCloud AWS environment. The attacker claimed to have exfiltrated data from databases within this environment. CareCloud's investigation found no evidence of further unauthorized activity after March 16, 2026.

While CareCloud initially acknowledged a breach in March, the full scope and details, including the number of affected individuals, became public following recent disclosures to state attorneys general, such as California's. The company had remained largely silent on specifics for four months after its initial admission.

The compromised information may include sensitive personal and financial data. This potentially encompasses names, home addresses, Social Security numbers, government identification numbers (like passports and driver's licenses), bank account details, and payment card numbers. A significant volume of medical and health information was also exposed, making the breach particularly valuable to identity thieves and health insurance fraudsters.

CareCloud provides cloud-based EHR, medical practice management, revenue cycle management, billing, and AI-powered software to over 45,000 providers across the United States. The company, which employs approximately 3,650 people, reported $120.5 million in revenue and $10.8 million in GAAP net income for fiscal year 2025.

The company has not yet provided technical details regarding how the security breach occurred, and no group has publicly claimed responsibility for the attack. This incident follows other recent healthcare data breaches, including one affecting 3.4 million people disclosed by Cognizant’s TriZetto Provider Solutions in March, and another confirmed by billing software provider Craneware, which impacted its hospital and pharmacy clients.

breachcloudfinance
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Week in review: Claude breached three companies during tests, AD CS domain-takeover PoC released

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Nono: Open-source sandbox for AI agents AI coding agents run with the same permissions as their users, meaning they can access sensitive files, credentials, and production systems. A prompt injection, hallucinated command, or simple mistake can quickly turn that access into a security incident. To red

breach

CISA Urges Utilities to Remove Internet-Exposed PLCs After Minnesota Attacks

After attacks hit 30+ Minnesota water systems, CISA urged utilities to remove internet-exposed PLCs and strengthen OT security. Between Sunday and Monday, July 26 and 27, a coordinated cyberattack hit operational technology (OT) systems at more than 30 community water utilities across the state, according to Minnesota IT Services (MNIT). “A coordinated cyberattack targeted operational technology [

vulnerability

COLDCARD wallet RNG flaw likely linked to $88 million Bitcoin theft

A vulnerability in COLDCARD hardware wallet firmware allowed attackers to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seeds were generated using a flawed random number generator. [...]

ai

SabPaisa Partners with AccuKnox for Zero Trust AI-Powered Cloud Security to Secure Its Payments Platform

CALIFORNIA, USA, 2nd August 2026, CyberNewswire

cloud

Welcome to Agents Week

Agents Week explores how cloud infrastructure must evolve to serve autonomous agents rather than human browsers. Join us as we unpack the storage, execution, and security primitives needed for an agent-native web.

security

Google Chrome may soon block New Tab hijacker extensions by default

Google is preparing a new Chrome security feature that would block policy-installed extensions from hijacking the New Tab page or changing the default search engine. [...]