Cognizant Technology Solutions, through its subsidiary TriZetto Provider Solutions, experienced a significant data breach that went undetected for nearly a year, exposing sensitive personal information such as Social Security numbers, financial account details, and home addresses. The breach, which affected at least 100 individuals across several states, led to multiple class-action lawsuits alleging delayed disclosure, insufficient notification to victims, and a lack of transparency regarding the incident's root cause and remediation. Plaintiffs argue that the delay in notification left affected individuals vulnerable to identity theft and financial fraud, while Cognizant and TriZetto have offered limited public comment due to ongoing litigation.
Separately, Covenant Health, a major healthcare provider operating in several northeastern US states, suffered a ransomware attack by the Qilin group in May 2025. The attack compromised the data of over 478,000 individuals, leading to system shutdowns across hospitals and clinics and prompting the organization to hire cybersecurity experts for containment and investigation. Covenant Health initially reported a smaller number of affected individuals but later updated the total to nearly half a million, subsequently notifying patients and offering credit monitoring and identity protection services. Both incidents underscore the persistent cybersecurity risks facing the healthcare sector and the significant impact of breaches on patient privacy and organizational trust.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
7 events from the most recent confirmed update back to the earliest known activity.
By January 2026, Cognizant was facing multiple U.S. class-action lawsuits over the TriZetto data breach. Plaintiffs alleged inadequate security, delayed notification, and lack of transparency that increased the risk of identity theft and fraud.
Following its investigation and regulatory reporting, Covenant Health notified affected individuals, offered credit monitoring and identity protection, and set up a dedicated call center. The notifications were issued in compliance with HIPAA and state requirements.
After further investigation, Covenant Health updated the number of affected individuals in December 2025 from about 7,800 to 478,188. The compromised data included personal, health, insurance, and treatment information.
TriZetto Provider Solutions discovered the breach on October 2, 2025, nearly a year after attackers first accessed its systems. The incident involved sensitive data including Social Security numbers, financial account details, and home addresses.
In June 2025, the Qilin ransomware group publicly claimed responsibility for the Covenant Health incident and said it had stolen 850 GB of sensitive data. This added public attribution and indicated the scale of the data theft.
In May 2025, Covenant Health suffered a ransomware attack attributed to the Qilin group, causing system shutdowns across multiple hospitals and clinics in several states. Operations were affected, though the organization said services continued with minimal disruption.
Attackers gained unauthorized access to systems at TriZetto Provider Solutions, a Cognizant healthcare subsidiary, as early as November 2024. The intrusion reportedly left sensitive personal data exposed for an extended period before discovery.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.