INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ApolloMD reveals 626,540 patients affected by May cyberattack
| 2026-02-12 18:29 DATA BREACH
Executive Summary
AI-generated
On May 22-23, 2025, the Georgia-based entity ApolloMD experienced a breach of protected health information, affecting an estimated 626,540 patients. The Qilin ransomware gang was behind the attack and publicly disclosed it on June 12, 2025, by posting five screenshots of files that did not contain patient information but claimed to have exfiltrated 238 GB of data. This included names, dates of birth, addresses, diagnoses, provider names, treatment information, health insurance information, and Social Security numbers for some individuals. The breach was notified to patients between July 21-September 11, 2025, with letters sent on September 17, 2025, while the incident remains unresolved as ApolloMD has not disclosed whether any ransom was paid or if all affected clients have opted to report the breach to HHS.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
da•••••.net
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Target & Sectors
Global Scope
Incident Timeline
Tactical Metrics
Intelligence Sources
Data Breaches
2026-02-12