Unlimited Technology Systems data incident

Unauthorized activity in Unlimited Technology Systems' commercial datacenter and acquisition of files containing patient information. Personal and protected health information copied from Unlimited's commercial datacenter.

Last modified

Summary

  • Environment: Not publicly identified
  • Operational impact: No outage or recovery duration quantified
  • Financial impact: No public cost estimate
  • Record status: Developing record. Reviewed August 9, 2026; updated as evidence emerges.

What happened

Unauthorized activity in Unlimited Technology Systems’ commercial datacenter and acquisition of files containing patient information. [2][3]

Impact

Personal and protected health information copied from Unlimited’s commercial datacenter. [2][4][5]

Documented data types include:

  • Names [2]
  • Contact information — Email, mailing address, and phone number; fields varied by individual. [2]
  • Health insurance information — Insurance policy, claims, benefits, and insurance-card information; fields varied by individual. [2]
  • Driver’s license numbers — Scanned driver’s licenses may have been included; fields varied by individual. [2]
  • Clinical information — Medical record number, dates of service, diagnosis information, and intake forms; fields varied by individual. [2]
  • Dates of birth [2]
  • Social Security numbers [2]

A cited record reports 277,364 individuals (Texans affected according to Texas Attorney General report BR-0005193; as of 2026-07-23). [2][4][5]

A cited record reports 3,836,316 individuals (Total individuals affected field in Texas Attorney General report BR-0005193; distinct from its Texas-resident count; as of 2026-07-23). [2][4][5]

A cited record reports 2,223 individuals (Massachusetts residents listed in incident record 2026-1197; this is not a national total; as of 2026-07-22). [2][4][5]

A cited record reports 3,803,750 individuals (Individuals listed for Unlimited in the HHS OCR incident portal; regulator-reported and not independently verified; as of 2026-08-08). [2][4][5]

Unlimited reported that the affected data did not include full patient medical records, medical imaging, credit-card information, or bank-account information. [2]

Unlimited found evidence that an unauthorized actor obtained a copy of some affected individuals’ personal information. [2]

Timeline

  1. Activity began

    Unauthorized activity in Unlimited Technology Systems’ commercial datacenter and acquisition of files containing patient information.

    [2]
  2. Documented activity ended

    End of the file-acquisition interval identified by Unlimited’s investigation.

    [2]
  3. Discovery

    Date Unlimited says it discovered unauthorized activity in its commercial datacenter.

    [2]
  4. Documented event

    California incident-list report date for Unlimited; the sample letter itself contains a date placeholder.

    [1]
  5. Briefing updated

    This briefing was last reviewed and updated on August 9, 2026.

Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT&CK technique.

Actors

  • No threat actor group has been identified in the reviewed public evidence.

TTPs

  • No specific MITRE ATT&CK technique is currently mapped for this case.

Response

Unlimited reported that it was unaware of attempted or actual misuse of information involved in the incident. Other potentially involved information included patient balances, other government identification, insurance cards, intake forms, and demographic information. Unlimited engaged a cybersecurity forensic firm, notified law enforcement, reviewed the affected data, and implemented enhanced security measures. Unlimited offered affected individuals two years of Kroll identity monitoring, including credit monitoring, fraud consultation, and identity-theft restoration. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2]