CSIDB logo
Incident

Unlimited Systems

Incident posture

Attack window
Oct 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-08-12 06:55

Linked entities

Victim
Unlimited Systems
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Oct 2025
Discovered
Oct 2025
Disclosed
Aug 2026
Resolved
Pending

Summary

Unlimited Systems reported a breach affecting approximately 3.8 million individuals linked to the 4,500 medical offices and 6,500 health care providers that use its billing services, with most of the impacted individuals being patients. The company discovered the incident, engaged a cybersecurity forensic firm, and determined that an unauthorized actor may have accessed personal information during the breach. It specializes in billing for medical specialists such as dermatologists, optometrists and oncologists, and is providing two years of free credit monitoring through Kroll to those affected. Breach monitoring groups have not observed the stolen data being shared on the dark web.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

Unlimited Systems, a Cincinnati-based medical billing system company, discovered a breach on October 19, 2025. After discovery, the company engaged a cybersecurity forensic firm to investigate the incident. The investigation determined that an unauthorized actor may have accessed personal information from October 5 through October 10, 2025. The breach affected approximately 3.8 million individuals associated with the 4,500 medical offices and 6,500 health care providers that use Unlimited Systems' billing platforms.

Most of the individuals receiving breach notices are patients of the medical specialists served by Unlimited Systems, which focuses on dermatologists, optometrists and oncologists. Unlimited Systems began sending breach notifications and is offering two years of free credit monitoring services from Kroll to all affected persons. The company has not disclosed the identity of the suspected attacker or attackers involved in the incident. As of August 9, 2026, breach tracking organization Rescana reported that it had not observed any posting of the compromised data on the dark web.

The Unlimited Systems breach is comparable in size to the TriZetto medical billing system breach disclosed in March, which affected 3.4 million records. It is considerably smaller than the Aflac breach disclosed the previous summer, which exposed about 23 million individuals. The announcement highlights the ongoing challenge of protecting sensitive health information systems and the reliance on Social Security numbers for verifying health plan participants. According to DeepStrike, a complete stolen medical record may still cost $500 or more for fraudulent use, while a typical stolen Social Security number was valued at only $1 in 2025.

Sources

Sources available to members: 1 source.

CSIDB