Data Breaches

3.8 Million Impacted by Unlimited Technology Systems Data Breach

Hackers stole personal, medical, and health insurance information from a company’s data center.

Data breach

Unlimited Technology Systems is notifying over 3.8 million individuals that their personal information was stolen in a data breach.

Based in Montgomery, Ohio, Unlimited provides advanced financial and revenue cycle technology to healthcare providers and organizations. It claims to be working with more than 4,500 oncology offices and over 6,500 specialty providers.

The incident, it says, was discovered in October 2025 and involved one of its commercial data centers. The company’s investigation determined that hackers stole certain data from its systems between October 5 and October 10, 2025.

The stolen data, Unlimited notes in a notification letter to the affected individuals, a copy of which was submitted (PDF) to the Iowa Attorney General’s Office, includes personal, medical, and health insurance information.

The hackers stole names, addresses, phone numbers, email addresses, Social Security numbers, medical record numbers, diagnoses, dates of service, insurance policy numbers, claims/benefits information, and scanned documents (such as driver’s licenses and government IDs).

“The data involved in the incident does not include full patient medical records, medical imaging, or financial information, such as credit card or bank account information,” Unlimited said.

Advertisement. Scroll to continue reading.

The company also notes that it is not aware of any attempted or actual misuse of the information compromised in the data breach.

In late July, the company notified the US Department of Health and Human Services (HHS) that 3,803,750 people were affected. The HHS added Unlimited to its breach portal on August 6.

The company is providing the affected people with two years of free credit monitoring, fraud consultation, and identity theft restoration services.

Unlimited has not named the threat actor responsible for the attack, and SecurityWeek has not seen any known extortion or ransomware groups claiming it.

Related: 311,000 Impacted by Brown Health Medical Group-MA Data Breach

Related: 150,000 Impacted by Madera Community Hospital Data Breach

Related: River Bank Says Hackers Deleted Data Stolen in Ransomware Attack

Related: Brinks Home Discloses Data Breach as Hackers Leak Files

Related Content

Data Breaches

Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them.

Data Breaches

Hackers stole personal information, medical records, and financial information from the organization’s server.

Data Breaches

An extortion group stole personal, financial, and medical information from the hospital’s network.

Data Breaches

The bank holding company was hacked in June, but the investigation into the incident continues.

Data Breaches

The physical security firm says its alarm monitoring and system functionality have not been affected.

Data Breaches

In March 2026, hackers stole personal, financial, and medical information from the company’s AWS environment.

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Data Breaches

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version