Everest ransomware claimed responsibility for a breach tied to Catalyst RCM, a third-party medical billing/revenue cycle management provider, resulting in exposure of data associated with diagnostic firm Vikor Scientific (now operating as Vanta Diagnostics) and affiliated labs. Reporting indicates suspicious activity was detected in Catalyst RCM’s secure file system in November 2025, with investigation finding misuse of an authorized login to access a server and copy data without permission. The incident was reported as affecting roughly 139,964–140,000 individuals, and Everest later posted the victim(s) to its Tor leak site and published allegedly stolen files after an apparent failure to reach payment.
Stolen data described across reporting includes a mix of personal, financial, and healthcare information, potentially including names, dates of birth, payment card data, and medical/diagnosis details; Everest also claimed theft of specific datasets (e.g., tens of thousands of PDFs totaling multiple gigabytes). Catalyst RCM reviewed the exposed information to determine impacted individuals and support notification efforts. Separate reporting on a ransomware-driven clinic shutdown at the University of Mississippi Medical Center describes a different, unrelated incident with no confirmed linkage to Everest or Catalyst RCM.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
By February 2026, the U.S. Department of Health and Human Services breach tracker listed Vikor Scientific as affected by the Catalyst RCM incident, with 139,964 individuals impacted. Reports noted the total could increase because other related entities had not yet separately reported to HHS.
After completing its review, Catalyst RCM notified affected individuals about the incident and offered free credit monitoring and identity restoration services. The company said it was not aware of any identity theft or fraud resulting from the breach.
By December 12, 2025, Catalyst RCM had finished its investigation and identified the individuals affected by the breach. The review found that personal, medical, insurance, and payment-related information may have been exposed.
In November 2025, the Everest ransomware group listed Vikor Scientific and its affiliated labs KorPath and Korgene on its Tor-based leak site, claiming responsibility for the attack. Reports said the group stole nearly 12 GB of documents.
In early November 2025, Catalyst RCM discovered that an authorized login had allegedly been misused to access a secure file management server and copy files without permission. The incident affected data tied to Vikor Scientific, now Vanta Diagnostics, and affiliated labs including KorPath and Korgene.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityaffairs.com
Open sourceteiss.co.uk
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.