DisclosureLens
GLOBALMalwareTechnologyInformationRansomwareSpacebearsRansom DemandedActor NamedMedium

Universal Software Solutions

bd_b323297db2cace05 · schema v1 · pii pii-v1

Severity

Medium

Discovered

Filed

Jun 24, 2025

To disclose

Affected

Not disclosed

Confidence

50%
Full breach record for Universal Software Solutions2 incidents on file

Threat-actor claim — not a regulatory filing

This row is a claim by the ransomware group Spacebears on its public extortion blog. It has not been validated by the victim or any regulator. Treat attribution and counts as the threat actor's assertion until a regulatory filing or victim disclosure corroborates them.

Group activity: TechnologyDiscovered: 2025-07-03

Source: Ransomware.live

Post text · scraped from the leak site

About UsAt Universal Software Solutions, we are passionate about revolutionizing the way healthcare professionals manage infusion therapy. Our mission is to streamline and enhance the infusion process, ensuring patients receive the best possible care with the utmost efficiency and safety.Who We AreFounded in 2000, Universal Software Solutions is a leader in infusion software solutions, dedicated to transforming healthcare delivery through innovative technology.Our team of experts combines extensive experience in software development, healthcare, and infusion therapy to create cutting-edge solutions that address the complex challenges faced by clinicians and patients alike.What We DoOur flagship product, Healthcare Data Management System (HDMS), is designed to simplify and automate the infusion software and HME/DME software workflows.With features like automated processes and customizable features, our software enhances accuracy and supports better clinical decision-making. By leveraging advanced technology and user-friendly design, we make it easier for healthcare professionals to focus on what matters most: patient care.Our ValuesInnovation: We are committed to pushing the boundaries of technology to provide cutting-edge solutions that address the evolving needs of the healthcare industry.Collaboration: We believe in working closely with our clients and partners to understand their needs and deliver solutions that exceed their expectations.Excellence: We strive for excellence in everything we do, from product development to customer service, ensuring that our solutions are reliable, efficient, and effective.Why Choose Us?Expertise: Our team brings together a wealth of knowledge in both software development and healthcare, ensuring that our solutions are not only technologically advanced but also clinically relevant.Customer-Centric Approach: We prioritize the needs

Incident timeline — mostly unverified

? — ?

Breach window unknown

Jun 24, 2025

Claim posted

No filing yet · watching

Compliance clocks stay unassessable until a regulatory filing lands. Dashed segments fill in automatically when corroboration arrives.

Claim → filing

Compliance clock

Not assessable

Tracked as a single-filing incident — the only disclosure on record for this event so far.Unverified claimView incident

Evidence ladder

Leak-site claimThis record

Attacker assertion only. Establishes: claim date, group, alleged victim.

Press / market report

Unlocks: incident narrative, operational impact. Still no compliance clock.

State AG / regulator filing

Unlocks: discovery date, data types, affected count, compliance clock.

SEC 8-K / victim statement

Unlocks: materiality, stated response, full audit trail. Ceiling removed.

No regulatory filing corroborates this yet — it is the attacker's own assertion. Watch this entity to be notified the moment a filing corroborates or contradicts it.

Source ceiling

  • actor name
  • victim claim
  • ransom/leak status
  • discovery date
  • materiality
  • notification
  • affected count
  • confirmed data types
  • compliance clock

The ✕ fields stay blank until a regulatory filing or victim disclosure lands.

About this groupFirst seen 2024-04-25

spacebears

According to ransomware.live, Space Bears is a double-extortion ransomware group that emerged in April 2024, distinguished by a professional "corporate" aesthetic on its leak site, leveraging Phobos RaaS infrastructure and targeting small-to-medium organizations in manufacturing, technology, and healthcare across the US and Europe.

157 tracked hereFull profile →