Veradigm's Third Breach in Two Years Skips Its Own Network
Security / news
Veradigm's Third Breach in Two Years Skips Its Own Network
The company's Sept. 8 filing says a stolen vendor credential exposed Social Security numbers through a single customer-service API, while the group claiming the breach says it has 3.5 million records.
A stolen credential for a single customer-service API, not a break-in to Veradigm's broader network, is what exposed patient Social Security numbers in the health technology company's third disclosed security incident in roughly two years. Veradigm said so in a filing with the Securities and Exchange Commission dated Sept. 8.
What the filing says, and what it leaves out
The Item 8.01 filing says an unauthorized party obtained credentials from a third-party vendor's environment for a Veradigm application programming interface used for customer services, then used that access to download copies of patient data, including Social Security numbers in some instances. Veradigm said no clinical or medical data was involved and that the compromised credentials provided access only through that limited interface, not to its broader network, servers or databases. The company said the incident caused no operational disruption, that it has notified law enforcement, and that affected customers and individuals are being notified with credit monitoring offered where applicable. The filing does not name the vendor, does not give a count of affected individuals, and does not name any attacker.
The number the filing does not confirm
A group calling itself the Gentlemen added Veradigm to its dark web leak site on Sept. 5, three days before Veradigm's filing, and claims to hold 3.5 million patient records, threatening to publish the data if a ransom is not paid. Veradigm's own filing describes the incident only as affecting "a small number of the Company's customers" and does not mention the Gentlemen by name or confirm any record count. Both figures can be true at once: a small number of corporate customers can still mean millions of individual patients, since each customer is typically a health system or practice. Neither Veradigm nor the SEC filing resolves which count, if either, is accurate. The six-day gap between the leak-site post and the filing is smaller than the disclosure gap this desk found in CISA's own catalog entry for a set of MikroTik RouterOS flaws, where a vendor's patch shipped before the researcher advisory it was responding to went public, but it is a reminder that a company's own timeline and an extortion group's timeline rarely arrive on the same day for the same reason.
The second breach in ten months, and the third in two
| Incident | Cause | Outcome |
|---|---|---|
| Began Dec. 2024, discovered July 1, 2025 | Stolen credentials used against a Veradigm storage account | 2,672,036 people affected; $10.5 million settlement approved March 2026 |
| Disclosed Sept. 8, 2026 | Stolen vendor credentials against a customer-service API | Investigation ongoing; no confirmed count |
HIPAA Journal, which has tracked Veradigm's disclosures, described the Sept. 8 incident as the company's third reported data security event in roughly two years, the second of which grew from an initial estimate of 70,000 people in September 2025 to 2,672,036 by a June 2026 update. That earlier breach produced a $10.5 million class-action settlement approved in March 2026, in which Veradigm denied wrongdoing. Vendor credentials, rather than a direct intrusion into Veradigm's own systems, are again the cause Veradigm points to, the same pattern that let a compromised registry credential spread through open-source packages in this month's disclosure of North Korea-linked attacks on Rust's crate registry. Veradigm said its investigation into the Sept. 8 incident is ongoing and that it has not yet determined whether the matter will have a material impact on its finances.
Sources
More in Security
- 01WordPress 7.1.1 Closes the Click2Shell Remote Code ChainResearcher Paulos Yibelo's chain turned one clicked link into server-side code execution by tricking WordPress into silently installing a theme with no authorization checks at all.
- 02Oracle's September Update Fixes Six Perfect-10 BugsNone of the maximum-severity flaws is confirmed under attack yet, but Oracle is now shipping security patches on a monthly rather than strictly quarterly calendar.
- 03Mathspace Breach Exposes Data on 1.08 Million StudentsAttackers had 17 days between reaching Mathspace's reporting database and downloading it, and the company patched the underlying Metabase flaw only after both had happened.
- 04BragJack Hijacks AI Agents Built Into Five BrowsersA single malicious extension could seize Chrome's Gemini, Edge's Copilot, Opera Neon, Perplexity Comet and Claude in Chrome without bypassing any model's guardrails or writing a single injected prompt.