Vikor Scientific
Incident posture
Linked entities
- Victim
- Vikor Scientific
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
Vikor Scientific, a healthcare diagnostic firm, disclosed that a data breach exposed the personal and medical information of nearly 140,000 individuals after the incident was recorded on the HHS breach tracker. The breach originated from Catalyst RCM, a revenue‑cycle management vendor that provides medical coding and billing services to the company and its affiliated labs KorPath and Korgene, where compromised credentials allowed attackers to access files containing names, dates of birth, payment card details, health insurance and medical data. Although the Everest ransomware group later listed the company and its affiliates KorPath and Korgene on its leak site, Catalyst’s investigation showed the data was taken from its systems, and the exact total of affected individuals remains uncertain because KorPath, Korgene and Catalyst have not reported their own counts to HHS.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
In mid‑November 2025 Catalyst RCM detected suspicious activity within its secure file management system and an investigation determined that compromised credentials had been used to access files containing names, dates of birth, payment card details, medical information and health insurance data. The accessed data was held by Catalyst as part of the medical coding and billing services it provides to Vikor Scientific, KorPath and Korgene. Later in November 2025 the Everest ransomware group listed Vikor Scientific, along with its affiliated diagnostic laboratory companies KorPath and Korgene, on its leak website and subsequently published data alleged to have been stolen from those companies, although the attackers did not target Vikor Scientific or its affiliates directly. The breach therefore originated from Catalyst RCM rather than from a direct attack on the diagnostic firms.
Catalyst published a data breach notice on its website earlier this month and notified the impacted individuals, while Vikor Scientific disclosed the breach and the U.S. Department of Health and Human Services tracker recorded that 139,964 individuals associated with Vikor Scientific (recently rebranded as Vanta Diagnostics) had their information compromised. KorPath and Korgene have not yet shared the number of affected individuals with HHS, leaving it uncertain whether the figure of 139,964 represents the total number of impacted people or if the actual count is higher. The compromised information includes personal identifiers and health‑related data as described in Catalyst’s investigation.
In response to the incident Catalyst conducted a forensic probe, identified the compromised credentials used by the attackers, and took steps to secure its file management system. Vikor Scientific, KorPath and Korgene have not disclosed additional remedial actions beyond the breach notifications already issued. The incident remains documented in the HHS breach tracker with the noted number of affected individuals.
Sources
Sources available to members: 1 source.