Veradigm Discloses Third Data Breach Exposing Patient Social Security Numbers

Veradigm Discloses Third Data Breach, Exposing Patient SSNs

HIGH
September 10, 2026
4m read
Data BreachSupply Chain AttackRegulatory

Impact Scope

People Affected

Potentially 3.5 million (unconfirmed)

Industries Affected

HealthcareTechnology

Geographic Impact

United States (national)

Related Entities

Threat Actors

The Gentlemen

Organizations

U.S. Securities and Exchange Commission (SEC)

Other

Full Report

Executive Summary

Chicago-based health technology firm Veradigm has reported its third data breach in under two years. In a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC) on September 8, 2026, the company disclosed that an unauthorized party gained access to a patient-facing API using stolen credentials from a third-party vendor. This access allowed the attacker to exfiltrate patient personal identifiers, critically including Social Security numbers (SSNs) in some instances. The incident highlights significant ongoing security challenges at the company and poses a serious risk of identity theft and fraud for the affected patients. The situation is complicated by an unverified claim from a ransomware group named 'The Gentlemen', which asserts it stole 3.5 million records.


Threat Overview

The attack vector was compromised credentials belonging to a third-party vendor. This is another example of a supply chain attack, where the security posture of a partner organization becomes the weak link. The attacker used these stolen credentials to directly access and query a patient-facing API, allowing them to systematically extract sensitive data.

While Veradigm stated that clinical or medical information was not compromised, the exposure of SSNs is highly significant. This type of data is immutable and highly prized by cybercriminals for creating synthetic identities, opening fraudulent lines of credit, and committing financial fraud.

Adding to the complexity, a group calling itself 'The Gentlemen' listed Veradigm on its dark web leak site around September 4-5, claiming to have stolen 3.5 million patient records. This claim has not been confirmed by Veradigm and could be an exaggeration or an entirely separate incident. However, it suggests that the company may be under pressure from an extortion attempt.

MITRE ATT&CK Techniques


Impact Assessment

The primary impact is on the patients whose Social Security numbers were exposed. They are now at high risk of long-term identity theft and financial fraud. The number of affected individuals has not yet been disclosed by Veradigm, but the claim of 3.5 million records, if accurate, would make this a major breach.

For Veradigm, this third breach in two years indicates a pattern of security failures that will likely attract intense regulatory scrutiny from the SEC and HHS (under HIPAA). The company faces significant financial penalties, legal liability from class-action lawsuits, and severe reputational damage. The ongoing costs of incident response, forensics, credit monitoring for victims, and legal fees will be substantial. The fact that the company is still managing fallout from a previous breach, including sending settlement checks, compounds the operational and financial strain.


IOCs — Directly from Articles

No specific technical Indicators of Compromise (IOCs) such as IP addresses, domains, or file hashes were mentioned in the source articles.


Detection & Response

  • API Security Monitoring: Organizations must implement robust monitoring for all APIs, especially those that are internet-facing and handle sensitive data. This includes anomaly detection for API requests, such as unusual request volumes, unexpected user agents, or requests from atypical geographic locations.
  • Rate Limiting and Throttling: Implement rate limiting on APIs to prevent attackers from rapidly exfiltrating large amounts of data through automated scripts.
  • Vendor Account Monitoring: All third-party and vendor accounts should be subject to heightened monitoring. Alerts should be configured for any suspicious activity associated with these accounts.

Mitigation

  1. Third-Party Credential Management: Stolen vendor credentials were the root cause. Veradigm and its partners must enforce strong security controls for all privileged accounts. This includes mandating phishing-resistant MFA, regular credential rotation, and just-in-time access.
  2. API Security Best Practices: Secure APIs by implementing strong authentication (e.g., OAuth 2.0), authorization, and input validation. Ensure that APIs do not expose more data than is absolutely necessary for their function.
  3. Vendor Risk Management: Continuously assess the security posture of all third-party vendors with access to your systems or data. This is not a one-time check but an ongoing process.
  4. Data Minimization: Review all data exposed via APIs and other systems to ensure that sensitive information like SSNs is only accessible when strictly required and is protected by additional layers of security.

Timeline of Events

1
September 4, 2026
Ransomware group 'The Gentlemen' claims to have breached Veradigm on a dark web leak site.
2
September 8, 2026
Veradigm files a Form 8-K with the SEC, officially disclosing the data breach.
3
September 10, 2026
This article was published

MITRE ATT&CK Mitigations

Mandating MFA for all accounts, especially vendor accounts with API access, is a critical control against credential theft.

Implement IP allow-listing and stricter access controls for vendor access to sensitive APIs.

Audit

M1047enterprise

Implement continuous monitoring and anomaly detection for API usage to quickly identify and respond to potential abuse.

Timeline of Events

1
September 4, 2026

Ransomware group 'The Gentlemen' claims to have breached Veradigm on a dark web leak site.

2
September 8, 2026

Veradigm files a Form 8-K with the SEC, officially disclosing the data breach.

Sources & References

Veradigm Data Breach 2026: New SEC Filing Exposes SSNs
Shattered (shattered.io) September 9, 2026

Article Author

Jason Gomes

Jason Gomes

• Cybersecurity Practitioner

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.

Threat Intelligence & AnalysisSecurity Orchestration (SOAR/XSOAR)Incident Response & Digital ForensicsSecurity Operations Center (SOC)SIEM & Security AnalyticsCyber Fusion & Threat SharingSecurity Automation & IntegrationManaged Detection & Response (MDR)

Editorial Standards & Analyst Review

CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.

Tags

Data BreachVeradigmHealthcareAPI SecuritySupply ChainRansomware

📢 Share This Article

Help others stay informed about cybersecurity threats

🎯 MITRE ATT&CK Mapped

Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.

🧠 Enriched & Analyzed

Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.

🛡️ Actionable Guidance

Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.

🔗 STIX Visualizer

Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.

Sigma Generator

Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.