LIVE · cybersecurity feed
Live wire
breach

Unlimited Technology Systems breach impacts 3.8 million people

Healthcare software company Unlimited Technology Systems reported that more than 3.8 million people were impacted by a data breach incident that occurred in October 2025. [...]

zeroday.news ·

Unlimited Technology Systems, a healthcare software provider, has confirmed a data breach impacting over 3.8 million individuals. The company specializes in financial and revenue cycle technology for specialty healthcare providers, serving approximately 4,500 clinics and 6,500 providers across the United States.

The breach, which occurred in October 2025, involved unauthorized access to a company server within its commercial data center. Unlimited Technology Systems detected suspicious activity on October 19, 2025, and initiated an investigation with the assistance of a cybersecurity forensic firm.

The investigation determined that an unauthorized actor accessed certain files between October 5 and October 10, 2025. During this five-day period, the attacker may have obtained copies of personal information belonging to patients of the healthcare providers Unlimited Technology Systems serves.

On July 1, 2026, Unlimited Technology Systems began submitting data breach notifications to authorities and distributing notices to affected patients. The U.S. Department of Health and Human Services' breach notification portal now lists the incident as affecting 3,803,750 people.

The types of data potentially exposed include full names, Social Security numbers, dates of birth, email and mailing addresses, phone numbers, and demographic information. More sensitive data such as scans of driver's licenses or other government IDs, insurance cards, intake forms, health insurance policy numbers, claims and benefits information, medical record numbers, and dates of service and diagnosis information were also at risk.

Unlimited Technology Systems has notified law enforcement about the incident. As of the company's disclosure on July 20, 2026, no ransomware or data-extortion groups have publicly claimed responsibility, and the perpetrators have not been identified.

Due to the nature of Unlimited Technology Systems' services, many affected patients may not have a direct relationship with the company itself, potentially causing confusion upon receiving a breach notification. To help mitigate the risks associated with the exposure of sensitive data, Unlimited Technology Systems is offering identity monitoring services through Kroll to those impacted.

breachhealthcare
ShareXLinkedInWhatsAppFacebook

More News

view all →
breachcritical

Metabase SQLi zero-day exploited in customer data-theft attacks

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]

malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

ai

AI chat bots are sliding into League of Legends friend requests

Chat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now?

security

Meta ordered to pay $942 million over harm to children

A new court ruling not only fined Meta to the extent of $942 million but also ordered it to improve its age assurance tools.

icshigh

Ex-NSA Chief Urges Disconnecting Water Controllers from Internet

Following suspected cyberattacks on water systems across at least 12 US states, likely perpetrated by Iran, a former NSA chief has strongly advised that industrial control systems like programmable logic controllers (PLCs) should not be connected to the internet. He emphasized the need for higher cybersecurity standards to defend these critical infrastructure components, noting that Iranian actors have a history and capability for such attacks.

nation-state

Water utilities group partners with DEF CON offshoot for Water Watch Center

The National Rural Water Association and a group of cybersecurity experts have formed a program to help cash-strapped utilities face the increase in threats to their systems.