
U.S.-based software developer Unlimited Technology Systems has revealed a cybersecurity breach that exposed sensitive personal information belonging to more than 3.8 million people.
Cincinnati, Ohio-based Unlimited Technology Systems is a software development company specialising in financial and revenue-cycle management solutions for specialty healthcare providers. The company’s technology serves more than 6,500 specialty providers and 4,500 clinical offices across the U.S., particularly in oncology and other specialty-care practices.
In a data security incident notice filed with the Office of Iowa Attorney General, Unlimited said that on October 19, it identified unauthorised activity within its commercial datacenter. The company immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.
It also took steps to secure the affected data center and notified relevant law enforcement authorities about the incident.
“Through this investigation, we determined that an unauthorised actor may have obtained a copy of some of your personal information between October 5 and October 10, 2025,” Unlimited said.
The compromised data included names, dates of birth, email, addresses, phone numbers, health insurance and patient balance information including insurance policy numbers, claims and benefits information, medical information, driver’s licenses and other government identifications, insurance cards, Social Security numbers and more.
The incident was reported to the US Department of Health and Human Services where Unlimited said it has identified as many as 3,803,750 people affected by the incident.
The software development company has urged all affected individuals to remain vigilant and monitor their credit reports and financial statements for any suspicious activities and to report suspicious activities to relevant law enforcement authorities and their banks.
It has also offered complimentary credit monitoring services through Kroll to all affected individuals.
At the time of publishing, no known hacker group claimed responsibility for the cyber attack on Unlimited. The company also did not share details on who was behind the attack, how much data was compromised, or whether it has received a ransom demand.
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543