Security News

Cybersecurity news aggregator

🏥
HIGH Attacks SecurityWeek

US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach

The breach stemmed from a ransomware attack by the Everest group, which gained unauthorized access to Catalyst RCM's secure file management system between November 8-9, 2025, using compromised valid login credentials. The attackers exfiltrated approximately 11-12 GB of sensitive data, including patient names, dates of birth, payment card details, medical histories, diagnoses, and health insurance information. The incident affected approximately 140,000 individuals whose data was processed by Catalyst RCM for diagnostic laboratories including Vikor Scientific (Vanta Diagnostics), KorPath, and Korgene.
Read Full Article →

Data Breaches US Healthcare Diagnostic Firm Says 140,000 Affected by Data Breach The Everest ransomware group has taken credit for a hacker attack on Vikor Scientific, now called Vanta Diagnostics. By Eduard Kovacs | February 23, 2026 (10:35 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Nearly 140,000 people are affected by a data breach disclosed by healthcare diagnostic company Vikor Scientific. The number of affected individuals came to light in recent days on the healthcare data breach tracker maintained by the US Department of Health and Human Services (HHS). However, the narrative is not straightforward. HHS’s tracker lists the South Carolina-based molecular diagnostics company Vikor Scientific (recently rebranded as Vanta Diagnostics) as the victim of a data breach that compromised the information of 139,964 individuals. The incident came to light in November 2025, when the Everest ransomware group listed Vikor Scientific, along with affiliated diagnostic laboratory companies KorPath and Korgene, on its leak website. The cybercriminals later published data allegedly stolen from the companies. However, the cybercriminals did not target Vikor and its affiliates directly. The data breach appears to stem from Catalyst RCM, a provider of revenue cycle management solutions. Advertisement. Scroll to continue reading. Catalyst published a data breach notice on its website earlier this month, revealing that it detected suspicious activity within its secure file management system in mid-November 2025. An investigation showed that compromised credentials had been used to access data. The company’s probe showed that the files stolen by the hackers stored names, dates of birth, payment card details, medical information, and health insurance information. The Everest ransomware group claimed to have stolen roughly 12GB worth of documents from Vikor, Korgene, and KorPath. According to Catalyst’s notification to impacted individuals, the compromised data was in its possession as a result of the medical coding and billing services it provides to Vikor Scientific, KorPath, and Korgene. Catalyst, KorPath, and Korgene have yet to share the number of impacted individuals with the HHS. It’s unclear whether 139,964 is the total number of affected people or if it’s higher. SecurityWeek has reached out to Catalyst RCM for clarification. Related : Mississippi Hospital System Closes All Clinics After Ransomware Attack Related : ApolloMD Data Breach Impacts 626,000 Individuals Related : Central Maine Healthcare Data Breach Impacts 145,000 Individuals Written By Eduard Kovacs Eduard Kovacs (@EduardKovacs) is the managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering. More from Eduard Kovacs BeyondTrust Vulnerability Exploited in Ransomware Attacks FBI: $20 Million Losses Caused by 700 ATM Jackpotting Attacks in 2025 Chip Testing Giant Advantest Hit by Ransomware PromptSpy Android Malware Abuses Gemini AI at Runtime for Persistence French Government Says 1.2 Million Bank Accounts Exposed in Breach Nearly 1 Million User Records Compromised in Figure Data Breach Ivanti Exploitation Surges as Zero-Day Attacks Traced Back to July 2025 German Rail Giant Deutsche Bahn Hit by Large-Scale DDoS Attack Latest News Ukrainian Gets 5 Years in US Prison for Aiding North Korean IT Fraud Autonomous AI Agents Provide New Class of Supply Chain Attack Romanian Hacker Pleads Guilty to Selling Access to US State Network Hundreds of FortiGate Firewalls Hacked in AI-Powered Attacks: AWS Recent RoundCube Webmail Vulnerability Exploited in Attacks Mississippi Hospital System Closes All Clinics After Ransomware Attack PayPal Data Breach Led to Fraudulent Transactions Critical Grandstream Phone Vulnerability Exposes Calls to Interception Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Identity Under Attack: Why Every Business Must Respond Now February 11, 2026 Attendees will walk away with guidance for how to build robust identity defenses, unify them under a consistent security model, and ensure business operations move quickly without compromise. Register Virtual Event: Ransomware Resilience & Recovery 2026 Summit February 25, 2026 SecurityWeek’s 2026 Ransomware Summit will discuss a roadmap for defending the enterprise, from mitigating root causes to mastering recovery, giving security teams the critical insights needed to navigate and neutralize today’s ransomware extortion threats. Submit People on the Move Wealth management platform Envestnet announced the appointment of Rich Friedberg as CISO. Yuneeb Khan has been named Chief Financial Officer of KnowBe4, succeeding Bob Reich, who is retiring. Cyera has appointed Brandon Sweeney as President, Shira Azran as Chief Legal Officer and Joseph Iantosca as Chief Financial Officer. More People On The Move Expert Insights How to Eliminate the Technical Debt of Insecure AI-Assisted Software Development Developers must view AI as a collaborator to be closely monitored, rather than an autonomous entity to be unleashed. Without such a mindset, crippling tech debt is inevitable. (Matias Madou) Security in the Dark: Recognizing the Signs of Hidden Information Security failures don’t always start with attackers, sometimes they start with missing truth. (Joshua Goldfarb) Living off the AI: The Next Evolution of Attacker Tradecraft Living off the AI isn’t a hypothetical but a natural continuation of the tradecraft we’ve all been defending against, now mapped onto assistants, agents, and MCP. (Etay Maor) Why We Can’t Let AI Take the Wheel of Cyber Defense The fastest way to squander the promise of AI is to mistake automation for assurance, and novelty for resilience. (Steve Durbin) The Upside Down is Real: What Stranger Things Teaches Us About Modern Cybersecurity To all those who are fighting the good fight in the world of cyber, keep collaborating to ensure our world never succumbs to the chaos of the Upside Down. (Nadir Izrael) Flipboard Reddit Whatsapp Whatsapp Email

Share this article