Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
third-party-vendor-breachransomware-group-operationhealthcare-sector-threatmass-credential-exposure

Everest Ransomware Attack on Catalyst RCM Exposes Vikor Scientific Patient Data

Updated 3mo agoFirst seen Feb 24, 20263 sources

Everest ransomware claimed responsibility for a breach tied to Catalyst RCM, a third-party medical billing/revenue cycle management provider, resulting in exposure of data associated with diagnostic firm Vikor Scientific (now operating as Vanta Diagnostics) and affiliated labs. Reporting indicates suspicious activity was detected in Catalyst RCM’s secure file system in November 2025, with investigation finding misuse of an authorized login to access a server and copy data without permission. The incident was reported as affecting roughly 139,964–140,000 individuals, and Everest later posted the victim(s) to its Tor leak site and published allegedly stolen files after an apparent failure to reach payment.

Stolen data described across reporting includes a mix of personal, financial, and healthcare information, potentially including names, dates of birth, payment card data, and medical/diagnosis details; Everest also claimed theft of specific datasets (e.g., tens of thousands of PDFs totaling multiple gigabytes). Catalyst RCM reviewed the exposed information to determine impacted individuals and support notification efforts. Separate reporting on a ransomware-driven clinic shutdown at the University of Mississippi Medical Center describes a different, unrelated incident with no confirmed linkage to Everest or Catalyst RCM.

Share:
Everest Ransomware Attack on Catalyst RCM Exposes Vikor Scientific Patient Data
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Feb 24, 20264mo ago

HHS breach tracker lists Vikor incident affecting 139,964 people

By February 2026, the U.S. Department of Health and Human Services breach tracker listed Vikor Scientific as affected by the Catalyst RCM incident, with 139,964 individuals impacted. Reports noted the total could increase because other related entities had not yet separately reported to HHS.

Dec 12, 20257mo ago

Catalyst RCM issues breach notifications and offers credit monitoring

After completing its review, Catalyst RCM notified affected individuals about the incident and offered free credit monitoring and identity restoration services. The company said it was not aware of any identity theft or fraud resulting from the breach.

Catalyst RCM completes review of affected individuals

By December 12, 2025, Catalyst RCM had finished its investigation and identified the individuals affected by the breach. The review found that personal, medical, insurance, and payment-related information may have been exposed.

Nov 15, 20258mo ago

Everest adds Vikor and affiliated labs to leak site

In November 2025, the Everest ransomware group listed Vikor Scientific and its affiliated labs KorPath and Korgene on its Tor-based leak site, claiming responsibility for the attack. Reports said the group stole nearly 12 GB of documents.

Nov 1, 20258mo ago

Unauthorized access at Catalyst RCM leads to data theft

In early November 2025, Catalyst RCM discovered that an authorized login had allegedly been misused to access a secure file management server and copy files without permission. The incident affected data tied to Vikor Scientific, now Vanta Diagnostics, and affiliated labs including KorPath and Korgene.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

9 LINKEDOpen in app
Threat actors
1 linked
Malware
1 linked
Organizations
7 linked
Catalyst RCMKorPathVikor ScientificKorGeneSecurityWeekVanta DiagnosticsSecurity Affairs
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.