HackingCustomer Data InvolvedIDENTITY_BASICIDENTITY_GOVERNMENTMediumContained
Medenet, Inc.
bd_f70eae5e09303287 · schema v1 · pii pii-v1
Full breach record for Medenet, Inc. →Medenet, Inc., a medical billing and software company, disclosed a cyber-attack occurring on December 26, 2025. The incident potentially exposed personal information, including names and government identifiers, of individuals across multiple states. Medenet engaged forensic specialists, secured systems, and reported the incident to the FBI. Affected individuals were offered two years of credit monitoring and fraud assistance provided by Cyberscout (a TransUnion company).
Massachusetts clock✗ MA AG >90d18 weeks discovery → filing
⚠ occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://www.mass.gov/doc/2026-873-medenet-inc-medenet/download
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- May 1, 2026
- Raw hash
- 29bf638bcac94bd80a7a660923e41315109096bcc734dc820ce54aa5ea4d2634
Reporting entity
- Name
- Medenet, Inc.norm: medenet
Victim entity
- Name
- Medenet, Inc.norm: medenet
Incident
- Discovered
- Dec 26, 2025
- Materiality determined
- —
- Notification sent
- May 28, 2026
- Affected individuals
- Not disclosed
- Data types
- IDENTITY_BASICIDENTITY_GOVERNMENT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1190 Exploit Public-Facing Application
- Threat actor
- External
- Regulator citations
- reported the incident to the Federal Bureau of Investigation
- Initial access
- exploit_public_facing
Compliance
- Time to disclose
- 18 weeks(126 days from discovery to filing)
- Compliance flags
- MA AG >90d
- Discovery-date grounding
- occurrence dateThe stored discovery date equals the breach OCCURRENCE date. Detection is normally later, so this OVERSTATES the delay — a 'late' verdict here may not be real.
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.