LIVE · cybersecurity feed
Live wire
breach

Unlimited Technology Systems Data Breach Exposes Data of 3.8 Million Healthcare Patients

Hackers stole personal, medical, and insurance data of 3.8 million people from Unlimited Technology Systems’ data center. Unlimited Technology Systems disclosed a data breach affecting more than 3.8 million people after hackers accessed one of its commercial data centers between October 5 and 10, 2025. Unlimited Technology Systems is a U.S.-based healthcare technology company headquartered […]

zeroday.news ·

Unlimited Technology Systems, a healthcare technology provider based in Montgomery, Ohio, has disclosed a data breach affecting over 3.8 million individuals. The company confirmed that unauthorized actors accessed one of its commercial data centers between October 5 and October 10, 2025, potentially compromising personal, medical, and insurance information.

The incident was discovered on October 19, 2025, when Unlimited Technology Systems identified unauthorized activity within its data center. Following this discovery, the company engaged a leading cybersecurity forensic firm to investigate the breach, notified law enforcement, and began a review of the affected data.

The investigation determined that an unauthorized actor may have obtained copies of certain personal information during the five-day access window. The potentially exposed data includes names, health insurance details, and medical information such as medical record numbers, diagnoses, and dates of service. Scanned documents like driver's licenses, insurance cards, and intake forms were also among the compromised data, along with Social Security numbers, dates of birth, addresses, email addresses, and phone numbers.

Unlimited Technology Systems clarified that the breach did not expose complete medical records, medical images, or payment card and bank account information. The company reported the incident to the U.S. Department of Health and Human Services, indicating that 3,803,750 individuals were affected.

At present, Unlimited Technology Systems has not provided technical details of the attack, nor has it identified the specific threat actor responsible. No known extortion groups have publicly claimed responsibility for the breach.

In response to the incident, Unlimited Technology Systems stated it has enhanced its security measures to mitigate the risk of future similar occurrences. The company is also offering two years of complimentary identity protection services through Kroll to all affected individuals. These services include credit monitoring, fraud consultation, and identity theft restoration support.

Unlimited Technology Systems provides financial, billing, and revenue cycle management solutions to healthcare organizations, supporting more than 4,500 oncology practices and over 6,500 specialty providers. Its platforms assist providers in managing payments, claims, and administrative operations.

breachhealthcare
ShareXLinkedInWhatsAppFacebook

More News

view all →
breachcritical

Metabase SQLi zero-day exploited in customer data-theft attacks

A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. [...]

malwarehigh

Living off the coding agent: Two tales of tunnels and LaunchAgents

Agent-parented reverse tunnels and LaunchAgents can expose a local admin app to the internet. Endpoint still needs to treat that as high severity even when the activity looks like vibe-coded ops, not confirmed malware.

ai

OpenAI pledges to add Astra security as Anthropic loosens Fable's leash

Or how I learned to stop worrying and love dangerous AI

ai

AI chat bots are sliding into League of Legends friend requests

Chat bots are sending friend requests in Riot immediately after ending your game. What are the scammers up to now?

security

Friday Squid Blogging: Arctic Bobtail Squid Video

Nice video of the Arctic bobtail squid. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

security

Meta ordered to pay $942 million over harm to children

A new court ruling not only fined Meta to the extent of $942 million but also ordered it to improve its age assurance tools.