Cyber Incident Victim: Unlimited Systems
Timeline
Summary
Unlimited Systems reported a breach affecting approximately 3.8 million individuals linked to the 4,500 medical offices and 6,500 health care providers that use its billing services, with most of the impacted individuals being patients. The company discovered the incident, engaged a cybersecurity forensic firm, and determined that an unauthorized actor may have accessed personal information during the breach. It specializes in billing for medical specialists such as dermatologists, optometrists and oncologists, and is providing two years of free credit monitoring through Kroll to those affected. Breach monitoring groups have not observed the stolen data being shared on the dark web.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 0 techniques |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Unlimited Systems, a Cincinnati-based medical billing system company, discovered a breach on October 19, 2025. After discovery, the company engaged a cybersecurity forensic firm to investigate the incident. The investigation determined that an unauthorized actor may have accessed personal information from October 5 through October 10, 2025. The breach affected approximately 3.8 million individuals associated with the 4,500 medical offices and 6,500 health care providers that use Unlimited Systems' billing platforms.

Most of the individuals receiving breach notices are patients of the medical specialists served by Unlimited Systems, which focuses on dermatologists, optometrists and oncologists. Unlimited Systems began sending breach notifications and is offering two years of free credit monitoring services from Kroll to all affected persons. The company has not disclosed the identity of the suspected attacker or attackers involved in the incident. As of August 9, 2026, breach tracking organization Rescana reported that it had not observed any posting of the compromised data on the dark web.
The Unlimited Systems breach is comparable in size to the TriZetto medical billing system breach disclosed in March, which affected 3.4 million records. It is considerably smaller than the Aflac breach disclosed the previous summer, which exposed about 23 million individuals. The announcement highlights the ongoing challenge of protecting sensitive health information systems and the reliance on Social Security numbers for verifying health plan participants. According to DeepStrike, a complete stolen medical record may still cost $500 or more for fraudulent use, while a typical stolen Social Security number was valued at only $1 in 2025.
