
RansomHub Leak Confirms Breach of Unlimited Technology Systems; 442,000 Patient Records at Risk
Encrygma analysts have confirmed that RansomHub published a 1.2TB data leak belonging to Unlimited Technology Systems on July 30, 2026, following a critical ransomware breach impacting 442,000 patients.
Executive Takeaway — TL;DR
- Category:
- Threat Intelligence
- Severity:
- Critical
- Actor Type:
- Ransomware Group
- Geography:
- North America
- Confidence:
- Confirmed
- Source:
- Unit 42
- Read Time:
- 4 min
Executive Summary
Encrygma Intelligence has monitored a significant escalation in the RansomHub ransomware group's campaign against the healthcare sector. On July 30, 2026, the group transitioned from private negotiation to public disclosure by leaking a 1.2TB archive of stolen data belonging to Unlimited Technology Systems (UTS), a major practice management and revenue cycle software vendor. The breach, which was officially disclosed by UTS on July 29, 2026, involves the sensitive medical and personal information of approximately 442,000 patients across multiple U.S. states. This development follows a period of infrastructure restoration at UTS, which was initially targeted in late 2025 but only recently confirmed the full scope of the exfiltration.
Threat Analysis
RansomHub has rapidly become the dominant Ransomware-as-a-Service (RaaS) player following the law enforcement disruptions of ALPHV and LockBit. Their current strategy involves "Big Game Hunting" with a focus on high-value third-party vendors whose compromise provides leverage over thousands of downstream clients. The attack on UTS demonstrates a classic double-extortion pattern: initial encryption of systems followed by a prolonged extortion phase during the recovery process. The leak suggests that UTS refused to meet the group's escalating demands, which often range from $10 million to $50 million for entities of this scale. The group's 90/10 commission split for affiliates continues to attract high-tier threat actors away from competing platforms.
Technical Details
Analysis of the UTS breach indicates the use of EDRKillShifter, a specialized malware designed to neutralize Endpoint Detection and Response (EDR) tools by leveraging vulnerable legitimate drivers (BYOVD - Bring Your Own Vulnerable Driver). Initial access was likely obtained through a sophisticated phishing campaign targeting remote access credentials of high-privilege employees. Once inside the network, the actors utilized Rclone for automated data exfiltration to a cloud repository before deploying the final encryptor. The ransomware variant used appears to be a derivative of the Knight (formerly Cyclops) codebase, modified for enhanced encryption speed on Linux-based ESXi environments. Forensic data shows the exfiltration phase lasted approximately six days between October 5 and October 10, 2025, but was only detected during the deployment of the encryption module.
Attribution Assessment
Encrygma attributes this activity to RansomHub with high confidence. The group's infrastructure overlaps significantly with former Scattered Spider and ALPHV affiliates. Their modus operandi includes a strict avoidance of CIS-based targets, consistent with Russian-nexus criminal operations. The specific leak site signatures, communication style observed in the UTS negotiations, and the use of the EDRKillShifter utility are all hallmarks of RansomHub’s current operational cycle. The transition to public leaking on July 30 matches the group's standard 72-hour final warning window post-negotiation failure.
Implications
The leak of UTS data poses severe long-term risks to the 442,000 impacted patients, including potential identity theft and targeted phishing attacks. For the healthcare industry, this incident highlights the critical vulnerability of the software supply chain. Small to medium-sized practices relying on UTS for practice management now face secondary extortion risks. Legal implications for UTS are mounting, with multiple class-action lawsuits filed in Iowa and South Carolina courts alleging failure to maintain adequate security protocols.
Recommendations
We recommend that organizations in the healthcare sector: 1) Implement phishing-resistant MFA for all remote access points and administrative portals. 2) Conduct immediate security audits of third-party software vendors with access to PII/PHI. 3) Deploy advanced EDR/XDR solutions with specialized protection against BYOVD techniques and driver blocklisting. 4) Maintain air-gapped, immutable backups to ensure rapid recovery without the need for ransom payments. 5) Monitor dark web leak sites for secondary mentions of subsidiary entities linked to the UTS supply chain.
Need Zero Click Spyware for Android and iOS?
Encrygma delivers serverless, offline, quantum-safe encrypted communications built for executives, agencies, and operators facing zero-click spyware and advanced mobile surveillance threats.
