Federal prosecutors in Maryland indicted former hospital pharmacist Matthew Bathula over an alleged eight-year campaign of unauthorized computer access tied to a Maryland medical system, identified in court records as Company A and reported to be the University of Maryland Medical Center. Investigators allege Bathula abused his role as a pharmacy clinical specialist from July 2016 through September 2024 to steal usernames, passwords, authentication cookies, images, videos, and other sensitive data from nearly 200 victims connected to the health system.
According to the indictment, Bathula used keyloggers, cookie theft tools, mailbox rules, file masquerading, and later spyware to maintain covert access to employee and affiliate accounts, including Gmail, Microsoft 365, Google Photos, iCloud Photos, social media, dating apps, and home security systems. Prosecutors say the activity enabled prolonged surveillance and, between February 2023 and July 2024, included covert video recording of victims without consent; the FBI said it identified and notified 195 victims nationwide within four months. Bathula faces two counts of unauthorized access to a protected computer and one count of aggravated identity theft, with potential prison exposure of up to 17 years, while civil lawsuits by current and former employees allege negligence, negligent supervision, negligent security, and invasion of privacy.

See attribution, scope, and your downstream exposure.
6 events from the most recent confirmed update back to the earliest known activity.
The case prompted civil litigation by at least six current and former employees alleging negligence, negligent supervision, negligent security, and invasion of privacy. The reference does not provide a specific filing date for those lawsuits.
On May 1, 2026, federal prosecutors in Maryland announced the indictment of Matthew Bathula on two counts of unauthorized access to a protected computer and one count of aggravated identity theft. If convicted, he faces up to 17 years in prison across the charged counts.
The FBI Baltimore Field Office said investigators identified and notified 195 victims located across the United States within four months. The references do not specify the exact start date of that notification effort.
The indictment says the unauthorized access and cyber spying campaign continued until September 2024. Over the course of the scheme, nearly 200 victims were allegedly affected through credential theft, mailbox-rule abuse, cookie theft, file masquerading, and other techniques.
Prosecutors allege that from February 2023 through July 2024, Bathula installed spyware on Company A computers to conduct covert surveillance. The alleged activity included recording victims without their consent and accessing highly private footage through compromised systems and accounts.
According to the indictment, Matthew Bathula began abusing his position as a pharmacy clinical specialist to gain unauthorized access to protected computers at a Maryland medical system identified as Company A. Prosecutors say the activity started in July 2016 and was used to steal credentials and other sensitive data from employees and affiliates.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
hipaajournal.com
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.