ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Operation PAR breach compromises personal data of nearly 150,000 individuals

A data security incident last year at Operation PAR exposed the sensitive personal information of nearly 150,000 individuals.

 

Headquartered in Pinellas Park, Florida, Operation PAR provides substance use disorder treatment, prevention, and recovery services. It is affiliated with Boley Centers and Eleos under the parent organisation Boley-PAR, Inc., with all three organisations sharing governance and administrative services while delivering complementary behavioral health programs.

 

In a data security incident notice published on its website, Operation PAR stated that on June 10, 2025, it identified issues within its computer network affecting its systems and those of its affiliated organisations, Boley and Eleos. The healthcare provider’s immediately launched an investigation, with assistance from external cyber security experts, to determine the nature and scope of the incident.

 

It also took steps to secure the affected systems and notified relevant law enforcement authorities about the same.

 

“Following the completion of our investigation, it was determined that some of our files may have been accessed or removed by the unauthorised individual(s) between June 6, 2025 and June 10, 2025. We conducted a thorough review of the potentially impacted data and on June 10, 2026, we determined that the impacted files may have contained your personal information,” Operation PAR said.

 

The compromised data included names and other personal identifiers including Social Security numbers. In a filing with the U.S. Department of Health and Human Services, Operation PAR said that it has identified at least 145,714 individuals impacted by the incident.

 

“In response to this incident and through our continuing comprehensive review, we have strengthened our network and implemented additional security improvements recommended by third-party cyber security experts,” Operation PAR added.

 

The healthcare provider has urged all affected individuals to remain vigilant and monitor their credit reports and financial statements for any suspicious activities and to report suspicious activities to relevant law enforcement authorities and their banks. 

 

It has also offered complimentary credit monitoring services through Epiq to all affected individuals.

 

In July 2025, the Worldleaks ransomware group claimed it had breached Operation PAR’s internal network, naming the healthcare provider as a victim on its data leak site. The group claimed to have obtained confidential information stolen from the organisation and threatened to release the data publicly if its ransom demands were not fulfilled.


Please take 30 seconds to register

Register Now

 

Already have an account? Sign in

Remember Login
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543