Oncology Institute Discloses Data Breach

2026-05-25T13:24:08Zbe1cd7ae7cf233d8e19aaf8f6c8e2abaf80b7056ec3361343903e3b4a4b90fde
CISACVE-2026-9082PHIbackdoorbotnetci-secrets-exfiltrationdata-breachdns-bypassdrupalgithub-actionshealthcareindustrial-exploitationkimwolflaravel-langmalwaremegalodonmythososs-vulnerabilitiessoftware-supply-chainsupply-chain-attacktelecom-outagethird-party-vendorunderminrvulnerability-scanning

What happened

Multiple high-impact security incidents and vulnerability reports were disclosed: several healthcare-related third‑party breaches (Oncology Institute — vendor possibly TriZetto; Radiology Associates of Richmond — ~266,000 impacted; DocketWise — ~143,000 impacted with SSNs, PHI) exposing names, PHI and financial data; large-scale supply‑chain attacks and repository compromises (5,500+ GitHub repos in the ‘Megalodon’ campaign; Laravel‑Lang packages poisoned to introduce backdoors and exfiltrate CI secrets); Anthropic’s Mythos tooling flagged ~23,000 potential vulnerabilities across ~1,000 OSS‑up

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
be1cd7ae7cf233d8e19aaf8f6c8e2abaf80b7056ec3361343903e3b4a4b90fde
Enrichment time
2026-05-25T13:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.