CONFERENCE Cloud & Data Security Summit - Watch Sessions on Demand
Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

Marketing, Law Firms Say Data Breaches Impact Over 200,000 People

Cierant Corporation and Zumpano Patricios independently disclosed data breaches, each impacting more than 200,000 individuals.

Marketing software and services company Cierant Corporation and law firm Zumpano Patricios have independently disclosed data breaches, each impacting more than 200,000 individuals.

What the Cierant and Zumpano Patricios incidents have in common is that the number of impacted people was brought to light in recent days by the healthcare data breach tracker maintained by the US Department of Health and Human Services (HHS).

The Zumpano Patricios breach impacts nearly 280,000 individuals. The law firm, which has offices in several major US cities, is representing healthcare providers in disputes with health insurance companies over medical service payments to patients. 

Zumpano Patricios is informing impacted individuals that it had detected an intrusion in its IT network on May 6, 2025, but could not determine the date and time of initial access. 

An investigation revealed that the hackers accessed and possibly exfiltrated files containing information such as patient name, date of birth, Social Security number, provider name, health insurer information, dates of service, and amounts charged by the provider and payments they received.

It’s unclear if the law firm was targeted in a ransomware attack — no known threat group has taken credit for the intrusion.

Advertisement. Scroll to continue reading.

In the case of Cierant, the HHS data breach tracker shows that more than 232,000 people are impacted.

In a data incident notice, the company revealed that it was targeted in late 2024 in the attacks in which the notorious Cl0p ransomware group exploited vulnerabilities in Cleo file transfer products to gain access to the files of organizations that had been using the impacted applications.

Cl0p targeted dozens of organizations through these vulnerabilities, and in some cases the victims were companies providing services to healthcare organizations. Some incidents have impacted a significant number of people.

Cierant was listed on Cl0p’s leak website as a victim of the Cleo attack in early February. The cybercriminals at some point claimed that the stolen files had been made public, but SecurityWeek was unable to verify those claims. 

Cierant, which had used Cleo’s VLTrader tool, said the compromised files stored personal and health data processed on behalf of third-party health plans.

“The types of personal information that may have been involved vary by person and can include the following: name, address, date of birth, treatment-related dates, a generic description of services received, provider name, medical record number, health plan beneficiary number, claims number, and/or plan member account number, premium information,” Cierant said. 

Many of the healthcare data breaches that came to light in recent months impacted hundreds of thousands and even millions of individuals.    

Related: 1.4 Million Affected by Data Breach at Virginia Radiology Practice

Related: Anne Arundel Dermatology Data Breach Impacts 1.9 Million People

Related: Compumedics Ransomware Attack Led to Data Breach Impacting 318,000

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Jazz has named Sean Robinson, Rickie Goyal, Danielle Guetta, Shani Nago, and Lior Magram as VPs and Michael Calev as COO.

AJ Shipley has been appointed Chief Product Officer at CrowdStrike.

Brinqa has named Ron Dovich as Chief AI and Automation Officer, David Allen as CTO, Steve Biagioni as CFO, and James Walta as VP of Product.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.