---
title: "Operation PAR, Boley Centers, and Eleos network incident"
description: "Evidence-backed account of Operation PAR, Boley Centers, and Eleos network incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/operation-par-boley-eleos-network-incident-2025"
markdown_url: "https://www.ally.security/incidents/operation-par-boley-eleos-network-incident-2025.md"
stix_url: "https://www.ally.security/incidents/operation-par-boley-eleos-network-incident-2025/stix.json"
---

# Operation PAR, Boley Centers, and Eleos network incident

Unauthorized access to a shared network and possible access or removal of files maintained by Operation PAR, Boley Centers, and Eleos. Potential exposure of patient or employee personal information in files accessed or removed from the affected network.

Last modified Aug 9, 2026 · 4 sources

## Summary

- **Environment:** Date the three organizations say they detected unauthorized network access.
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized access to a shared network and possible access or removal of files maintained by [Operation PAR](https://www.operationpar.org/), Boley Centers, and Eleos. [1](#source-1)

## Impact

Potential exposure of patient or employee personal information in files accessed or removed from the affected network. [2](#source-2) [3](#source-3) [4](#source-4)

Documented data types include:

- Names [2](#source-2)
- Health insurance information — Operation PAR's June 24 update says categories varied by individual; none of these fields is asserted for every person or for the other two organizations. [2](#source-2)
- Clinical information [2](#source-2)
- Dates of birth [2](#source-2)
- Social Security numbers [2](#source-2)
- Driver's license numbers [2](#source-2)
- Financial account information [2](#source-2)

A cited record reports 145,714 individuals (Individuals listed for Operation PAR in the HHS OCR incident portal; regulator-reported and not independently verified; as of 2026-08-08). [2](#source-2) [3](#source-3) [4](#source-4)

A cited record reports 375 individuals (Massachusetts residents affected according to incident report 2026-1031; not a national total; as of 2026-06-25). [2](#source-2) [3](#source-3) [4](#source-4)

The joint notice says some files may have been accessed or removed by one or more unauthorized individuals; it does not identify them or the access method. [1](#source-1)

At the time of the joint notice, the organizations said they had no evidence the recipient's information had been used for financial fraud or identity theft. [1](#source-1)

## Timeline

### June 6, 2025 — Activity began

Start of the possible file-access or removal interval identified in the joint notice. [1](#source-1)

### June 10, 2025 — Discovery

Date the three organizations say they detected unauthorized network access. [1](#source-1)

### June 10, 2025 — Documented activity ended

End of the possible file-access or removal interval identified in the joint notice. [1](#source-1)

### June 10, 2026 — Documented event

Date the organizations say their review determined that impacted files may have contained personal information. [1](#source-1)

### June 25, 2026 — Public disclosure

Date Operation PAR says it began notifying affected individuals and date reported to Massachusetts OCA and HHS OCR. [2](#source-2)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

The organizations say they secured the network, investigated with external cybersecurity professionals, strengthened the network, and implemented additional third-party recommendations; Operation PAR also says it reported the incident to law enforcement. The joint notice offered complimentary Epiq one-bureau credit monitoring and identity-protection features; the coverage length was redacted in the sample reviewed. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [1](#source-1)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/operation-par-boley-eleos-network-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Joint cybersecurity-incident notice — Massachusetts filing

official · Operation PAR, Inc.; Boley Centers, Inc.; PEMHS dba Eleos

<https://www.mass.gov/doc/2026-1031-operation-par-inc/download>

<a id="source-2"></a>

### Notice of Data Security Incident — June 24, 2026 update

official · Operation PAR, Inc.

<https://www.operationpar.org/_files/ugd/e73d40_fe6305a42d324101bdc9646192f626a7.docx?dn=PAR++-+Website+Notice%2838997021.1%29.docx>

<a id="source-3"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<a id="source-4"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Affected Organization · 100% confidence · current**  
   June 2025 Operation PAR, Boley, and Eleos network incident: Personal Enrichment through Mental Health Services, Inc.
2. **Affected Organization · 100% confidence · current**  
   June 2025 Operation PAR, Boley, and Eleos network incident: Operation PAR, Inc.
3. **Resulted In · 100% confidence · current**  
   June 2025 Operation PAR, Boley, and Eleos network incident: The organizations say they secured the network, investigated with external cybersecurity professionals, strengthened the network, and implemented additional third-party recommendations; Operation PAR also says it reported the incident to law enforcement.
4. **Resulted In · 100% confidence · current**  
   June 2025 Operation PAR, Boley, and Eleos network incident: Operation PAR, Boley, and Eleos affected-individual notification
5. **Affected Individual Count · 100% confidence · current**  
   Operation PAR, Boley, and Eleos data exposure: 145,714 individual
6. **Discovered At · 100% confidence · current**  
   June 2025 Operation PAR, Boley, and Eleos network incident: 2025-06-10
7. **Exposed Data Category · 100% confidence · current**  
   Operation PAR, Boley, and Eleos data exposure: Names
8. **Resulted In · 100% confidence · current**  
   June 2025 Operation PAR, Boley, and Eleos network incident: The joint notice says some files may have been accessed or removed by one or more unauthorized individuals; it does not identify them or the access method.
9. **Exposed Data Category · 100% confidence · current**  
   Operation PAR, Boley, and Eleos data exposure: Health insurance information
10. **Exposed Data Category · 100% confidence · current**  
   Operation PAR, Boley, and Eleos data exposure: Clinical information
11. **Resulted In · 100% confidence · current**  
   Operation PAR, Boley, and Eleos affected-individual notification: At the time of the joint notice, the organizations said they had no evidence the recipient's information had been used for financial fraud or identity theft.
12. **Disclosed At · 100% confidence · current**  
   June 2025 Operation PAR, Boley, and Eleos network incident: 2026-06-25
13. **Affected Organization · 100% confidence · current**  
   June 2025 Operation PAR, Boley, and Eleos network incident: Boley Centers, Inc.
14. **Ended At · 100% confidence · current**  
   June 2025 Operation PAR, Boley, and Eleos network incident: 2025-06-10
15. **Resulted In · 100% confidence · current**  
   Operation PAR, Boley, and Eleos affected-individual notification: The joint notice offered complimentary Epiq one-bureau credit monitoring and identity-protection features; the coverage length was redacted in the sample reviewed.
16. **Exposed Data Category · 100% confidence · current**  
   Operation PAR, Boley, and Eleos data exposure: Dates of birth
17. **Exposed Data Category · 100% confidence · current**  
   Operation PAR, Boley, and Eleos data exposure: Social Security numbers
18. **Exposed Data Category · 100% confidence · current**  
   Operation PAR, Boley, and Eleos data exposure: Driver's license numbers
19. **Affected Individual Count · 100% confidence · current**  
   Operation PAR, Boley, and Eleos data exposure: 375 individual
20. **Exposed Data Category · 100% confidence · current**  
   Operation PAR, Boley, and Eleos data exposure: Financial account information
21. **Occurred At · 100% confidence · current**  
   Operation PAR, Boley, and Eleos data exposure: 2026-06-10
22. **Began At · 100% confidence · current**  
   June 2025 Operation PAR, Boley, and Eleos network incident: 2025-06-06
23. **Resulted In · 100% confidence · current**  
   June 2025 Operation PAR, Boley, and Eleos network incident: Operation PAR, Boley, and Eleos data exposure

</details>
