Potentially 3.5 million (unconfirmed)
Chicago-based health technology firm Veradigm has reported its third data breach in under two years. In a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC) on September 8, 2026, the company disclosed that an unauthorized party gained access to a patient-facing API using stolen credentials from a third-party vendor. This access allowed the attacker to exfiltrate patient personal identifiers, critically including Social Security numbers (SSNs) in some instances. The incident highlights significant ongoing security challenges at the company and poses a serious risk of identity theft and fraud for the affected patients. The situation is complicated by an unverified claim from a ransomware group named 'The Gentlemen', which asserts it stole 3.5 million records.
The attack vector was compromised credentials belonging to a third-party vendor. This is another example of a supply chain attack, where the security posture of a partner organization becomes the weak link. The attacker used these stolen credentials to directly access and query a patient-facing API, allowing them to systematically extract sensitive data.
While Veradigm stated that clinical or medical information was not compromised, the exposure of SSNs is highly significant. This type of data is immutable and highly prized by cybercriminals for creating synthetic identities, opening fraudulent lines of credit, and committing financial fraud.
Adding to the complexity, a group calling itself 'The Gentlemen' listed Veradigm on its dark web leak site around September 4-5, claiming to have stolen 3.5 million patient records. This claim has not been confirmed by Veradigm and could be an exaggeration or an entirely separate incident. However, it suggests that the company may be under pressure from an extortion attempt.
T1078.004 - Cloud Accounts: The attacker used stolen vendor credentials to access a cloud-hosted API.T1190 - Exploit Public-Facing Application: The patient-facing API was the public-facing asset that was abused.T1020 - Automated Exfiltration: The attacker likely used scripts to systematically query the API and exfiltrate data.T1486 - Data Encrypted for Impact: If the 'The Gentlemen' claim is related, ransomware could be involved, although not confirmed by Veradigm.The primary impact is on the patients whose Social Security numbers were exposed. They are now at high risk of long-term identity theft and financial fraud. The number of affected individuals has not yet been disclosed by Veradigm, but the claim of 3.5 million records, if accurate, would make this a major breach.
For Veradigm, this third breach in two years indicates a pattern of security failures that will likely attract intense regulatory scrutiny from the SEC and HHS (under HIPAA). The company faces significant financial penalties, legal liability from class-action lawsuits, and severe reputational damage. The ongoing costs of incident response, forensics, credit monitoring for victims, and legal fees will be substantial. The fact that the company is still managing fallout from a previous breach, including sending settlement checks, compounds the operational and financial strain.
No specific technical Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were mentioned in the source articles.
Mandating MFA for all accounts, especially vendor accounts with API access, is a critical control against credential theft.
Implement IP allow-listing and stricter access controls for vendor access to sensitive APIs.
Ransomware group 'The Gentlemen' claims to have breached Veradigm on a dark web leak site.
Veradigm files a Form 8-K with the SEC, officially disclosing the data breach.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.