CyberIntel ⬡ News
★ Saved ◆ Cyber Reads
← Back 🛡 Active Threats Mar 23, 2026

3.7 Million Telehealth Patients Allegedly Affected By Two Recent Breaches

DataBreaches.net Archived Mar 23, 2026 ✓ Full text saved

He hasn’t attracted much attention or media coverage yet, and he doesn’t have any leak site or Telegram account. However, those reporting breaches involving patient data should note a threat actor known as “Stuckin2019” (or simply “Stuck”). Two of his recent attacks allegedly affected telehealth entities and 3.7 million patients. OpenLoop Health On January 7,... Source

Full text archived locally
✦ AI Summary · Claude Sonnet


    He hasn’t attracted much attention or media coverage yet, and he doesn’t have any leak site or Telegram account. However, those reporting breaches involving patient data should note a threat actor known as “Stuckin2019” (or simply “Stuck”). Two of his recent attacks allegedly affected telehealth entities and 3.7 million patients. OpenLoop Health On January 7, 2026, “Stuckin2019” listed patient data from OpenLoop Health for sale on a popular hacking forum. The listing and the data samples provided as proof of claims were removed two days later. OpenLoop did not appear to have issued any statement or response to the alleged breach until March 18, when the Iowa firm notified the Texas Attorney General’s Office that 68,160 Texans were affected. Texas does not make reports publicly available on its breach site, so that the report may be unrelated to the January 7 listing, but it seems likely that it is. According to Stuckin2019’s forum listing, he acquired data on 1.6 million patients. One sample included patients’ names, email addresses, postal addresses, heights and weights, medical information, and biometric data. A second sample contained patients’ contact information, prescription information, and FedEx tracking information. [ Note: On inquiry, Stuck indicated that Stuckin2019 was one male individual and not a group .] In addition to its report to the Texas Attorney General’s Office, OpenLoop also notified the California Attorney General’s Office. That report did not disclose the number of patients affected but stated that they learned of the breach on January 7 and that access to their system occurred between January 7 and January 8. The notification to patients , signed by Justin Pingel, OpenLoop’s Chief Privacy Officer, stated that the incident did not include access to electronic health records, Social Security numbers, or financial account information. Affected patients have been offered one year of identity and credit monitoring service, provided by IDX. The letter does not mention any extortion demand or payment to the threat actor. A potential class-action lawsuit was filed in the U.S. District Court for the Southern District of Iowa on February 16. The plaintiff is Kathy Morehart. DataBreaches contacted Stuckin2019 via Tox to request an update on the incident. According to Stuck, he regretted listing the incident because he had intended to contact OpenLoop first to see if they could get them to pay not to leak the data. OpenLoop reportedly agreed to pay him, and the listing was removed. Stuck did not disclose the amount of the payment but stated that the data were not republished anywhere and had been deleted. “I deleted it, all that remains is the 2 samples that I have posted on my pixeldrain account,” Stuck told DataBreaches. Before the notification to California was posted online, DataBreaches had contacted OpenLoop to ask whether they had confirmed the number of patients to be notified and when they would mail notifications to affected patients. DataBreaches has received no reply. Zealthy, Too OpenLoop Health was not the only telehealth business associate and provider attacked by Stuckin2019. On January 16, “Stuck” posted a listing for Zealthy data on a popular hacking forum. He would later re-post it on a second forum. According to what Stuck told DataBreaches in a chat on Tox, he first emailed the New York-based virtual care provider between January 15 and January 20. Zealthy reportedly locked him out but did not reply to any of his emails. The Zealthy listing claims that the scope of the breach includes “Full Names, Email Addresses, Phone Numbers, Addresses, Drivers Licenses, Patient Information, Employees, Important Documents, etc.” According to Stuck, 2.1 million patient records were acquired. And as he did with OpenLoop, “Stuck” provided some proof of claims. In this case, the sample included unredacted images of driver’s licenses, as well as personal and protected health information of five patients. Patient information included first and last name, email address, postal address, phone number, date of birth, patient ID, and diagnosis (e.g., morbid obesity, type 2 diabetes, etc.). DataBreaches could not find any substitute notice or press release from Zealthy regarding the alleged breach, and emailed Zealthy to request additional information. DataBreaches also emailed the five patients whose information was included in the sample to ask whether they had been notified that their data had been stolen and leaked online. No replies have been received. DataBreaches reminds readers that neither OpenLoop nor Zealthy has issued any statements either confirming or disputing some of Stuck’s claims. If they reply to this site’s inquiries, this post will be updated. DataBreaches also notes that this is not Zealthy’s first privacy-related incident. In 2024, the Department of Justice and the Federal Trade Commission took enforcement action against several telehealth firms for unfair and deceptive data-collection, tracking, and sharing practices. Zealthy was one of the firms the government took action against. “But Wait, There’s More….?” Stuckin2019 mentioned to DataBreaches that these were not the only medical entities he had recently attacked. He would not reveal who the other entities are or discuss how he gains access to his targets. He did, however, answer a question about why he used Allison Nixon of Unit 221B’s picture as his profile picture on one forum. “My friend sent it to me on social network. I didn’t know who it was,” he wrote. He declined to respond to a follow-up question as to whether his friend is part of ScatteredLapsus$Hunters. Category: Breach Laws Hack Health Data Subcontractor U.S.
    💬 Team Notes
    Article Info
    Source
    DataBreaches.net
    Category
    🛡 Active Threats
    Published
    Mar 23, 2026
    Archived
    Mar 23, 2026
    Full Text
    ✓ Saved locally
    Open Original ↗