No shortage of unauthorized intrusions by third parties this month. A new data breach against Unlimited Technology Systems, a practice management and revenue cycle software vendor, has compromised the personal and medical records of 442,000 patients. Last October, an unauthorized intruder managed to access these files, deploying ransomware and compromising such data as health insurance information, service dates, Social Security numbers and other types of identification.

After discovering the attack, the company suspended access to their systems, contacted law enforcement, opened an investigation, and notified affected patients. As a third party software provider, United Technology serves healthcare organizations across multiple states in the US, all of which are now exposed thanks to this one incident.
In non-medtech news, a ransomware attack has also struck a dairy subsidiary of Coca-Cola named Fairlife, stealing company data and temporarily halting production at Fairlife’s four manufacturing facilities in the US. Although the company has not verified the nature of the stolen data, a certain ransomware added Fairlife to its dark web site shortly after the incident to the tune of 1TB. I know what you’re thinking, but surprisingly it’s not ShinyHunters this time, rather a group called Anubis, which emerged in late 2024 and operates as a Ransomware-as-a-Service (RaaS) platform. The hackers threatened to publish the data if the company did not entertain negotiations.
Another unauthorized party struck a second blow against Aflac’s Japanese branch last month, stealing the personal data of over 4 million customers. The hackers hit the company’s customer-facing policyholder portal and other connected systems, exposing names, birth dates, security details, insurance and bank account information. This is the second massive breach to hit Aflac since 2025, though it’s not yet clear if the two events are linked. Back then, Aflac said social engineering was responsible for the unauthorized network access, which was detected and stopped within hours. Even so, the total number of people affected then was over 22 million, dwarfing what we know so far of this breach.
Two breaches in such quick succession could lead to a formal review or stricter reporting requirements for the insurer.
Unauthorized intrusions into a company’s network represent a weakness in some part of the defense, whether a lack of encryption, human error (internal or external), or other substandard security protocols. When 73% of 600 security leaders surveyed say their organizations are not prepared for a major cyberattack, citing a lack of cohesion and visibility from the top down.
To get a head start on falling in with the remaining 27%, take a look at our free Beginner’s Guide to Encryption for Compliance and Data Protection here.