CSIDB logo
Incident

Korgene

Incident posture

Attack window
Nov 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-17 16:46

Linked entities

Victim
Korgene
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Nov 2025
Discovered
Nov 2025
Disclosed
Feb 2026
Resolved
Pending

Summary

A healthcare diagnostic firm (Vikor Scientific, recently rebranded as Vanta Diagnostics) and its affiliated laboratory companies KorPath and Korgene were exposed after a breach at their revenue‑cycle management provider, Catalyst RCM, allowed attackers to access stored files. The compromised data included names, dates of birth, payment card details, medical information and health insurance information, and the U.S. Department of Health and Human Services tracker records that the firm’s breach affected approximately 140,000 individuals, though the exact total remains uncertain because Catalyst, KorPath and Korgene have not disclosed their own counts.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

In mid‑November 2025 Catalyst RCM detected suspicious activity within its secure file management system and launched an investigation that determined compromised credentials had been used to gain access to stored files. The investigation revealed that the accessed files contained names, dates of birth, payment card details, medical information, and health insurance information belonging to individuals whose data Catalyst held as part of its medical coding and billing services for Vikor Scientific, KorPath, and Korgene. Catalyst subsequently published a data breach notice on its website in early February 2026, disclosing the detection timeline and the types of data involved. Around the same time in November 2025 the Everest ransomware group added Vikor Scientific, KorPath, and Korgene to its leak website and later published data it claimed had been stolen from those companies. The U.S. Department of Health and Human Services breach tracker recorded the incident under Vikor Scientific, indicating that 139,964 individuals were affected, though Catalyst, KorPath, and Korgene have not yet provided their own impact numbers to HHS, leaving it uncertain whether the total exceeds that figure.

The compromised data exposed a combination of personal identifiers and sensitive health and financial details, increasing the risk of identity theft, fraud, and misuse of medical information for those whose records were processed by Catalyst for the three affiliated companies. The publication of the alleged stolen data by the Everest ransomware group amplified the potential for harm, as the information became publicly accessible. Vikor Scientific’s disclosure to the HHS tracker contributed to the official record of the breach, while the lack of corresponding reports from Catalyst, KorPath, and Korgene means the full scope of impact remains unclear. The breach thus affected a substantial pool of individuals whose medical billing and coding data was handled through Catalyst’s systems.

In response, Catalyst RCM issued a breach notification to affected individuals after confirming the unauthorized access through its investigation. Vikor Scientific reported the incident to the HHS breach tracker, providing the documented figure of 139,964 affected individuals. Catalyst, KorPath, and Korgene have not yet shared the number of impacted individuals with HHS, and the article does not detail any further containment or remediation steps beyond the notice and investigation. The incident remains recorded in public breach tracking sources as a significant exposure of personal and health data linked to the three companies.

Sources

Sources available to members: 1 source.

CSIDB