Nearly 140,000 patients affected: the Vanta Diagnostics case and the risk of stolen credentials
Introduction
Cyberattacks on the healthcare sector are steadily increasing, targeting not only large hospital facilities but also diagnostic companies and medical laboratories. When the data at stake concerns people’s health, the consequences can be particularly severe. The case of Vanta Diagnostics, made public between late 2025 and early 2026, is a concrete example of how a breach can propagate through the supply chain and affect tens of thousands of individuals.
What Happened
Vanta Diagnostics, a US-based healthcare diagnostics company formerly known as Vikor Scientific, was hit by a ransomware attack. The group responsible is Everest, a criminal group well known for this type of attack. The criminals gained access to the systems not by directly bypassing Vanta’s defenses, but by exploiting stolen credentials belonging to Catalyst RCM, a third-party company that provided services to the firm. Using these credentials, the attackers were able to access protected electronic health data, known as ePHI (Electronic Protected Health Information), meaning sensitive medical information belonging to patients. The Everest group published the data on their website in November 2025. The US Department of Health and Human Services (HHS) recorded the incident in January 2026, while Vanta Diagnostics issued a formal acknowledgment in February 2026. The number of individuals affected is between 139,964 and 140,000.
Why It Matters
This incident highlights an increasingly widespread problem: companies are compromised not only through their own vulnerabilities, but also through those of the partners and vendors with whom they share access and data. In the healthcare sector, this is particularly sensitive. Medical information is among the most sensitive data that exists and, once stolen, can be used for insurance fraud, blackmail, or sold on illegal markets. The patients involved bear no responsibility and are often not even informed in time to protect themselves.
What Companies and Users Can Do
Companies should regularly review access permissions granted to third-party vendors, implement multi-factor authentication systems, and continuously monitor their systems for anomalous activity. For potentially affected patients, it is advisable to pay close attention to suspicious communications that use personal data, review bank and insurance statements, and, where available, activate a credit monitoring service. Anyone who fears they may be among those affected can contact Vanta Diagnostics directly to request clarification.
Final Takeaways
The supply chain is often the weakest link in an organization’s cybersecurity posture.
Stolen credentials remain one of the most effective and underestimated attack vectors.
In the healthcare sector, timely communication to affected individuals is essential and not always guaranteed.
Sources:
https://www.roguevault.news/vanta-diagnostics-data-breach-140000-patients/
https://radar.offseq.com/threat/us-healthcare-diagnostic-firm-says-140000-affected-8cf2ff6f
https://www.securityweek.com/us-healthcare-diagnostic-firm-says-140000-affected-by-data-breach/
Source: SecurityWeek