---
title: "Unlimited Technology Systems data incident"
description: "Evidence-backed account of Unlimited Technology Systems data incident, covering what happened, impact, timeline, attack vector, technical details, and primary sources."
incident_type: "Data incident"
status: "active"
last_modified: "2026-08-09"
canonical_url: "https://www.ally.security/incidents/unlimited-technology-systems-data-incident-2025"
markdown_url: "https://www.ally.security/incidents/unlimited-technology-systems-data-incident-2025.md"
stix_url: "https://www.ally.security/incidents/unlimited-technology-systems-data-incident-2025/stix.json"
---

# Unlimited Technology Systems data incident

Unauthorized activity in Unlimited Technology Systems' commercial datacenter and acquisition of files containing patient information. Personal and protected health information copied from Unlimited's commercial datacenter.

Last modified Aug 9, 2026 · 6 sources

## Summary

- **Environment:** Not publicly identified
- **Operational impact:** No outage or recovery duration quantified
- **Financial impact:** No public cost estimate

## What happened

Unauthorized activity in [Unlimited](https://www.unlimitedsystems.com/) Technology Systems' commercial datacenter and acquisition of files containing patient information. [2](#source-2) [3](#source-3)

## Impact

Personal and protected health information copied from Unlimited's commercial datacenter. [2](#source-2) [4](#source-4) [5](#source-5)

Documented data types include:

- Names [2](#source-2)
- Contact information — Email, mailing address, and phone number; fields varied by individual. [2](#source-2)
- Health insurance information — Insurance policy, claims, benefits, and insurance-card information; fields varied by individual. [2](#source-2)
- Driver's license numbers — Scanned driver's licenses may have been included; fields varied by individual. [2](#source-2)
- Clinical information — Medical record number, dates of service, diagnosis information, and intake forms; fields varied by individual. [2](#source-2)
- Dates of birth [2](#source-2)
- Social Security numbers [2](#source-2)

A cited record reports 277,364 individuals (Texans affected according to Texas Attorney General report BR-0005193; as of 2026-07-23). [2](#source-2) [4](#source-4) [5](#source-5)

A cited record reports 3,836,316 individuals (Total individuals affected field in Texas Attorney General report BR-0005193; distinct from its Texas-resident count; as of 2026-07-23). [2](#source-2) [4](#source-4) [5](#source-5)

A cited record reports 2,223 individuals (Massachusetts residents listed in incident record 2026-1197; this is not a national total; as of 2026-07-22). [2](#source-2) [4](#source-4) [5](#source-5)

A cited record reports 3,803,750 individuals (Individuals listed for Unlimited in the HHS OCR incident portal; regulator-reported and not independently verified; as of 2026-08-08). [2](#source-2) [4](#source-4) [5](#source-5)

Unlimited reported that the affected data did not include full patient medical records, medical imaging, credit-card information, or bank-account information. [2](#source-2)

Unlimited found evidence that an unauthorized actor obtained a copy of some affected individuals' personal information. [2](#source-2)

## Timeline

### October 5, 2025 — Activity began

Unauthorized activity in Unlimited Technology Systems' commercial datacenter and acquisition of files containing patient information. [2](#source-2)

### October 10, 2025 — Documented activity ended

End of the file-acquisition interval identified by Unlimited's investigation. [2](#source-2)

### October 19, 2025 — Discovery

Date Unlimited says it discovered unauthorized activity in its commercial datacenter. [2](#source-2)

### July 21, 2026 — Documented event

California incident-list report date for Unlimited; the sample letter itself contains a date placeholder. [1](#source-1)

### August 9, 2026 — Briefing updated

This briefing was last reviewed and updated on August 9, 2026.

## Threat Group & Attack Vector

The cited public record does not establish a specific initial-access vector, malware family, exploited vulnerability, or ATT\&CK technique.

### Actors

- No threat actor group has been identified in the reviewed public evidence.

### TTPs

- No specific MITRE ATT\&CK technique is currently mapped for this case.

## Response

Unlimited reported that it was unaware of attempted or actual misuse of information involved in the incident. Other potentially involved information included patient balances, other government identification, insurance cards, intake forms, and demographic information. Unlimited engaged a cybersecurity forensic firm, notified law enforcement, reviewed the affected data, and implemented enhanced security measures. Unlimited offered affected individuals two years of Kroll identity monitoring, including credit monitoring, fraud consultation, and identity-theft restoration. No access path, attribution, scale, or recovery detail is inferred beyond the cited claims. [2](#source-2)

## Assets

[Download the case-scoped STIX 2.1 bundle](<https://www.ally.security/incidents/unlimited-technology-systems-data-incident-2025/stix.json>)

## Sources

Primary source records used to research this incident.

<a id="source-1"></a>

### Data Security Breach List — 2026 records

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/privacy/databreach/list>

<a id="source-2"></a>

### Notice of Data Breach — California sample

official · Unlimited Technology Systems, LLC

<https://oag.ca.gov/system/files/Unlimited%20-%20Exhibit%20A%20-%20Sample%20Individual%20Notice.pdf>

<a id="source-3"></a>

### Submitted breach notification sample — Unlimited Technology Systems

regulatory · California Department of Justice, Office of the Attorney General

<https://oag.ca.gov/ecrime/databreach/reports/sb24-626846>

<a id="source-4"></a>

### Data Security Breach Reports — 2026 public records

regulatory · Office of the Attorney General of Texas

<https://www.texasattorneygeneral.gov/consumer-protection/data-breach-reporting>

<a id="source-5"></a>

### 2026 Data Breach Notification Report

regulatory · Massachusetts Office of Consumer Affairs and Business Regulation

<https://www.mass.gov/doc/data-breach-report-2026/download>

<a id="source-6"></a>

### Breach Portal current investigation table

regulatory · U.S. Department of Health and Human Services Office for Civil Rights

<https://ocrportal.hhs.gov/ocr/breach/breach_report_hip.jsf>

<details>
<summary>Evidence ledger</summary>

Review the supporting structured claims.

1. **Exposed Data Category · 100% confidence · current**  
   Unlimited customer-patient data exposure: Names
2. **Resulted In · 100% confidence · current**  
   October 2025 Unlimited commercial-datacenter incident: Unlimited reported that it was unaware of attempted or actual misuse of information involved in the incident.
3. **Occurred At · 100% confidence · current**  
   Unlimited affected-individual notification: 2026-07-21
4. **Resulted In · 100% confidence · current**  
   Unlimited customer-patient data exposure: Unlimited reported that the affected data did not include full patient medical records, medical imaging, credit-card information, or bank-account information.
5. **Resulted In · 100% confidence · current**  
   October 2025 Unlimited commercial-datacenter incident: Unlimited customer-patient data exposure
6. **Exposed Data Category · 100% confidence · current**  
   Unlimited customer-patient data exposure: Contact information
7. **Affected Individual Count · 100% confidence · current**  
   Unlimited customer-patient data exposure: 277,364 individual
8. **Resulted In · 100% confidence · current**  
   Unlimited customer-patient data exposure: Other potentially involved information included patient balances, other government identification, insurance cards, intake forms, and demographic information.
9. **Began At · 100% confidence · current**  
   October 2025 Unlimited commercial-datacenter incident: 2025-10-05
10. **Resulted In · 100% confidence · current**  
   October 2025 Unlimited commercial-datacenter incident: Unlimited affected-individual notification
11. **Exposed Data Category · 100% confidence · current**  
   Unlimited customer-patient data exposure: Health insurance information
12. **Discovered At · 100% confidence · current**  
   October 2025 Unlimited commercial-datacenter incident: 2025-10-19
13. **Exposed Data Category · 100% confidence · current**  
   Unlimited customer-patient data exposure: Driver's license numbers
14. **Exposed Data Category · 100% confidence · current**  
   Unlimited customer-patient data exposure: Clinical information
15. **Exposed Data Category · 100% confidence · current**  
   Unlimited customer-patient data exposure: Dates of birth
16. **Affected Individual Count · 100% confidence · current**  
   Unlimited customer-patient data exposure: 3,836,316 individual
17. **Exposed Data Category · 100% confidence · current**  
   Unlimited customer-patient data exposure: Social Security numbers
18. **Ended At · 100% confidence · current**  
   October 2025 Unlimited commercial-datacenter incident: 2025-10-10
19. **Resulted In · 100% confidence · current**  
   October 2025 Unlimited commercial-datacenter incident: Unlimited engaged a cybersecurity forensic firm, notified law enforcement, reviewed the affected data, and implemented enhanced security measures.
20. **Affected Individual Count · 100% confidence · current**  
   Unlimited customer-patient data exposure: 2,223 individual
21. **Affected Individual Count · 100% confidence · current**  
   Unlimited customer-patient data exposure: 3,803,750 individual
22. **Resulted In · 100% confidence · current**  
   Unlimited customer-patient data exposure: Unlimited found evidence that an unauthorized actor obtained a copy of some affected individuals' personal information.
23. **Resulted In · 100% confidence · current**  
   October 2025 Unlimited commercial-datacenter incident: Unlimited offered affected individuals two years of Kroll identity monitoring, including credit monitoring, fraud consultation, and identity-theft restoration.
24. **Affected Organization · 100% confidence · current**  
   October 2025 Unlimited commercial-datacenter incident: Unlimited Technology Systems, LLC

</details>
