Cyber Incident Victim: Unlimited Technology Systems, LLC
Date:
Oct 2025
Location:
United States of America
Summary
Unlimited Technology Systems, LLC experienced a breach when an unauthorized actor accessed files containing patient information handled by its practice management software. The intrusion was detected during an internal security review, prompting the company to engage a forensic firm and notify law enforcement. Exposed data included names, Social Security numbers, birth dates, contact details, scanned identification documents, health insurance information, medical record numbers, service dates and diagnosis details. No ransomware group has claimed responsibility, and the attacker has not been publicly identified. The incident prompted a class‑action investigation by a national law firm seeking remedies for affected individuals.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 0 motives | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
On October 19, 2025, Unlimited Technology Systems, LLC detected unauthorized activity within its commercial data center and promptly initiated an investigation with the assistance of a cybersecurity forensic firm. The investigation determined that between October 5, 2025, and October 10, 2025, an unauthorized actor accessed files and may have obtained copies of personal information belonging to patients of the healthcare providers that Unlimited serves. Unlimited stated that it notified law enforcement and conducted a review of the data involved. The company later disclosed the incident to state regulators, including through a sample notice submitted to the Iowa Attorney General's Office on July 1, 2026.

The breach may have compromised both personally identifiable information and protected health information. Potentially exposed personally identifiable information includes names, Social Security numbers, dates of birth, email and mailing addresses, phone numbers, demographic information, and scanned documents such as copies of driver's licenses or other government identification, insurance cards, and intake forms. Potentially exposed protected health information includes health insurance policy numbers, claims and benefits information, medical record numbers, dates of service, and diagnosis information. As of Unlimited's disclosure, no data extortion or ransomware group has publicly claimed responsibility for the attack, and Unlimited has not publicly identified the responsible threat actor.
Patients of healthcare providers that use Unlimited's practice management software face an increased risk of identity theft and fraud as a result of the incident. Edelson Lechtzin LLP is investigating a potential class action to pursue legal remedies on behalf of individuals whose sensitive personal and protected health information may have been compromised. Unlimited has established a dedicated assistance line at 844-576-3063 for individuals with questions about the breach. The total number of individuals affected nationwide has not been publicly disclosed.
