CSIDB logo
Incident

ApolloMD

Incident posture

Attack window
May 2025
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-02 10:54

Linked entities

Victim
ApolloMD
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
May 2025
Discovered
Pending
Disclosed
Pending
Resolved
Pending

Summary

A ransomware attack exposed the personal and protected health information of over 626,000 individuals affiliated with a network of physicians and practices managed by an Atlanta-based healthcare services provider. The cyberattack occurred over a two-day period, during which the threat actors gained access to files containing names, addresses, dates of birth, diagnostic details, provider names, dates of service, treatment information, and health insurance data, with Social Security numbers also impacted for some individuals. The Qilin ransomware group claimed responsibility by listing the company on its Tor-based leak site shortly after the incident. Notification letters and complimentary credit monitoring services were offered to affected individuals beginning in the months following the breach, and the U.S. Department of Health and Human Services later confirmed the total number of impacted individuals on its data breaches portal.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

2 techniques

Description

Between May 22 and May 23, 2025, ApolloMD, an Atlanta, Georgia-based provider of integrated, multispecialty physician, practice, and advanced practice clinician management services, experienced a cyberattack in which an unauthorized actor gained access to files containing personally identifiable information and protected health information. The company supports more than 125 practices across 18 states and works with over 2,500 physicians and advanced practice clinicians, placing a large amount of sensitive medical and personal data within the environment that was targeted. According to the company's own incident notice, the intrusion occurred over a two-day window, suggesting that the attacker had sufficient time within the network to locate and extract the relevant files before being detected or expelled.

The information stolen during the incident included full names, postal addresses, dates of birth, diagnostic details, provider names, dates of service, treatment information, and health insurance information for affiliated physicians, practices, and their patients. For some individuals, the exposed records also included Social Security numbers, raising the severity of the breach and the potential for identity theft and financial fraud. Because ApolloMD operates as a business associate to numerous healthcare organizations, the compromised data spanned a wide network of affiliated medical providers and their patient populations, amplifying the overall impact of the intrusion.

Although ApolloMD did not publicly attribute the attack to a specific threat actor, the Qilin ransomware group added the company to its Tor-based leak site in early June 2025, indicating the group's likely involvement in both the intrusion and the subsequent data theft. The timing of the leak site listing, appearing weeks after the initial May 22–23 access window, aligns with typical ransomware group behavior of publishing victim data when extortion demands are not met. The presence of the company on the leak site confirmed that data had been exfiltrated and was being used as leverage in a double-extortion scheme.

By September 2025, ApolloMD had completed its internal investigation and review of the affected data sufficiently to begin notifying the affiliated physicians and practices of the incident. The company subsequently began mailing individual notification letters to the impacted people, informing them of the specific categories of their information that had been exposed. As part of its response, ApolloMD offered free credit monitoring services to the affected individuals, a standard remediation measure intended to help detect potential misuse of the stolen personal and financial information. The delay between the May intrusion and the September notifications reflects the time typically required to identify the scope of the breach, review the compromised files, and prepare compliant communications for a large affected population.

The scale of the breach became public in February 2026 when the US Department of Health and Human Services added ApolloMD to its data breaches portal, disclosing that 626,540 individuals had been impacted by the incident. This figure represented the cumulative count of patients, physicians, and other individuals whose personal or protected health information was contained within the accessed files. The disclosure on the HHS portal provided the most concrete quantification of the breach's reach, confirming that the incident affected hundreds of thousands of people across the multiple states in which ApolloMD and its affiliated practices operate.

Following the public confirmation of the breach, ApolloMD continued to face the consequences of the exposure of sensitive medical and personal data belonging to over 626,000 individuals. The combination of detailed health records, insurance information, dates of birth, addresses, and in some cases Social Security numbers created a substantial risk of medical identity theft, insurance fraud, and targeted phishing attempts against the affected population. The notification letters mailed in September 2025, along with the credit monitoring services offered at that time, represented the primary direct response available to the impacted individuals as the company worked to address the aftermath of the intrusion.

Sources

Sources available to members: 2 sources.

CSIDB