Classaction Excelas Data Breach Exposes Sensitive Personal and Health Information
Article Content
- •Unauthorized access to Excelas systems occurred between November 27 and December 3, 2025.
- •Cl0p ransomware group claimed responsibility for the breach on January 23, 2026.
- •Excelas is offering 24 months of complimentary identity monitoring services to affected individuals.
Excelas, a medical record organization, reported a data breach involving unauthorized access to its systems between November 27 and December 3, 2025. The breach was detected on January 28, 2026, and may have compromised personal and health information of individuals, including names, Social Security numbers, and medical records. The ransomware group Cl0p claimed responsibility for the breach on January 23, 2026, posting on the dark web. Excelas has begun notifying affected individuals and is offering complimentary identity monitoring services for 24 months. The breach was disclosed to attorneys general in Massachusetts and New Hampshire on May 12, 2026. Excelas is working with law enforcement and cybersecurity specialists to enhance security measures.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Cl0p and Excelas in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cleo Harmony Vulnerability Exploited for Privilege Escalation A newly discovered authentication bypass vulnerability in Cleo Harmony, tracked as CVE-2026-84115, allows remote attackers to escalate privileges by manipulating JWT refresh tokens. The flaw, found in the '/api/connections' function, enables attackers to bypass access controls through crafted HTTP headers. An exploit…