Skip to main content
Back to overview
Medium

The Oncology Institute Reports Third-Party Cyber Attack Impacting Patient Information

U.S.

Key points

  • Reported on May 26, 2026.
  • Caused by a third-party cyber attack.
  • Impacted patient information held within systems of a third-party software vendor.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Ransomware

Nation State Or Named Threat Actor actor profile

03

Potential impact

Data Exposure

Confidentiality, Availability

Published
May 26, 2026
Updated
Jul 22, 2026
Confidence
Medium
Evidence
5 sources

Structured assessment

Signal analysis

This analysis groups the signal by industry, likely incident action and impacted security area. It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Nation State Or Named Threat Actor actor profile

Watch ransomware, endpoint compromise and business interruption exposure.

  • Source type: supplier or third-party involvement
  • Actor profile: Nation State Or Named Threat Actor

Business impact

Potential operational disruption
Impact area
Confidentiality, Availability
Likely asset
User or customer data, Server or cloud data store

Mentioned entities

TheoncologyinstituteData DisclosureThe Oncology Institute Reports Third-PartyU.S. CISADD-WRTLangflow and WordPressKnown Exploited VulnerabilitiesOpenAI AIHugging FacePublic PoC

Quick context

Questions about this signal

What happened in this signal?

U.S. CISA adds DD-WRT, Langflow and WordPress flaws to its Known Exploited Vulnerabilities catalog OpenAI AI models exploited zero-days to reach Hugging Face in benchmark test Public PoC triggers active exploitation of critical SharePoint RCE vulnerability CVE-2026-50522 Zimbra 10.1.20 patches multiple security issues, including a critical command injection bug Qilin Ransomware Affiliates Abuse CVE-2026-0257 to Gain Unauthorized VPN Access Dutch Intelligence Warns Russia Uses Hacked IP Cameras for Military Espionage Critical 7-Zip Flaw Allows Code Execution by Opening Crafted XZ-Compressed Files. Update it now! CVE-2026-42533: Critical NGINX Bug Could Turn HTTP Requests Into Server Takeovers AI Agents Turned Into Attackers: Hugging Face Reveals Autonomous Intrusion Campaign Volexity Uncovers Zero-Day Campaign Targeting SonicWall VPN Appliances Attackers Can Take Over WordPress Sites Using Newly Released wp2shell Exploits OpenSSL Fixes HollowByte Memory Exhaustion Bug Daxin: 13-Year-Old China-Linked Malware Found Still Active on Manufacturer's Network U.S. CISA adds Fortinet FortiSandbox and Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog Ernst & Young (EY) Investigates Data Breach Involving Third-Party Support Tickets A cyberattack hit Nichirei, one of Japan's largest food companies New Russian Campaign Uses Fake Webex and Zoom Installers to Deploy Starland RAT U.S. CISA adds KNX Association KNX Protocol Connection Authorization Option 1 and Oracle flaws to its Known Exploited Vulnerabilities catalog A deeper insight into the CloudWizard APT’s activity revealed a long-running activity Experts warn of a threat actor, tracked as CloudWizard APT, that is targeting organizations involved in the region of the Russo-Ukrainian conflict. On March 2023, researchers from Kaspersky spotted a previously unknown APT group, tracked as Bad Magic (aka Red Stinger), that targeted organizations in the region of the Russo-Ukrainian conflict. The attackers were observed using PowerMagic and CommonMagic implants. Looking for other implants with similarities with PowerMagic and CommonMagic, the researchers identified a different cluster of even more sophisticated malicious activities associated with the same threat actor. The victims of this cluster were located not only in the Donetsk, Lugansk and Crimea regions, but also in central and western Ukraine. The APT group targeted individuals, as well as diplomatic and research organizations in the area of the conflict. In the latest campaign uncovered by Kaspersky, the APT group, used a modular framework dubbed CloudWizard that supports spyware capabilities, including taking screenshots, microphone recording, harvesting Gmail inboxes, and keylogging. The Oncology Institute reports patient data potentially exposed in third-party vendor breach The Oncology Institute has confirmed that patient information was impacted in a cybersecurity incident involving a third-party software provider. The healthcare network first disclosed the security breach in November 2025, while the vendor’s investigation was still ongoing, as reported by Security Affairs. The Oncology Institute disclosed on May 20, 2026, that Kroll, a third-party administrator for an unnamed vendor, detected unauthorized access to systems that may have affected patient data. This incident follows a larger breach at Cognizant-owned TriZetto Provider Solutions in March 2026, which exposed sensitive information for over 3.4 million patients. The TriZetto breach, which began in November 2024, involved unauthorized access to records for insurance eligibility verification transactions, potentially exposing names, addresses, Social Security numbers, and insurance details. While no ransomware group has claimed responsibility for either incident, the potential exposure of patient data highlights significant risks within the healthcare supply chain. The Oncology Institute stated that the vendor has established a patient portal to provide information and address inquiries related to the breach.

When was this signal reported?

Shadow Tier lists May 26, 2026 as the signal date.

Which organization is connected to this signal?

Theoncologyinstitute is the organization connected to this public signal.

Explore Theoncologyinstitute
Which attack pattern is relevant?

This signal is connected to current ransomware incidents based on its reported incident context.

Explore current ransomware incidents
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence