Korgene
Incident posture
Timeline
Summary
A healthcare diagnostic firm (Vikor Scientific, recently rebranded as Vanta Diagnostics) and its affiliated laboratory companies KorPath and Korgene were exposed after a breach at their revenue‑cycle management provider, Catalyst RCM, allowed attackers to access stored files. The compromised data included names, dates of birth, payment card details, medical information and health insurance information, and the U.S. Department of Health and Human Services tracker records that the firm’s breach affected approximately 140,000 individuals, though the exact total remains uncertain because Catalyst, KorPath and Korgene have not disclosed their own counts.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In mid‑November 2025 Catalyst RCM detected suspicious activity within its secure file management system and launched an investigation that determined compromised credentials had been used to gain access to stored files. The investigation revealed that the accessed files contained names, dates of birth, payment card details, medical information, and health insurance information belonging to individuals whose data Catalyst held as part of its medical coding and billing services for Vikor Scientific, KorPath, and Korgene. Catalyst subsequently published a data breach notice on its website in early February 2026, disclosing the detection timeline and the types of data involved. Around the same time in November 2025 the Everest ransomware group added Vikor Scientific, KorPath, and Korgene to its leak website and later published data it claimed had been stolen from those companies. The U.S. Department of Health and Human Services breach tracker recorded the incident under Vikor Scientific, indicating that 139,964 individuals were affected, though Catalyst, KorPath, and Korgene have not yet provided their own impact numbers to HHS, leaving it uncertain whether the total exceeds that figure.
The compromised data exposed a combination of personal identifiers and sensitive health and financial details, increasing the risk of identity theft, fraud, and misuse of medical information for those whose records were processed by Catalyst for the three affiliated companies. The publication of the alleged stolen data by the Everest ransomware group amplified the potential for harm, as the information became publicly accessible. Vikor Scientific’s disclosure to the HHS tracker contributed to the official record of the breach, while the lack of corresponding reports from Catalyst, KorPath, and Korgene means the full scope of impact remains unclear. The breach thus affected a substantial pool of individuals whose medical billing and coding data was handled through Catalyst’s systems.
In response, Catalyst RCM issued a breach notification to affected individuals after confirming the unauthorized access through its investigation. Vikor Scientific reported the incident to the HHS breach tracker, providing the documented figure of 139,964 affected individuals. Catalyst, KorPath, and Korgene have not yet shared the number of impacted individuals with HHS, and the article does not detail any further containment or remediation steps beyond the notice and investigation. The incident remains recorded in public breach tracking sources as a significant exposure of personal and health data linked to the three companies.
Sources
Sources available to members: 1 source.