Three Asheville-area skilled nursing and rehabilitation facilities affiliated with Ascent Healthcare Management disclosed that a threat actor accessed systems or accounts between November 25 and November 28, 2025, exposing files tied to an unnamed trusted vendor. The affected organizations—Bear Mountain Health and Rehabilitation, Elevate Health & Rehabilitation, and Swannanoa Valley Health & Rehabilitation—said the compromised information included extensive personal data and protected health information, and they began notifying affected residents on July 31.
The breach was separately reported to HHS, with 1,397, 1,551, and 1,045 individuals affected across the three facilities. A Massachusetts template notice reportedly stated that the intrusion involved login credentials stolen from another unnamed trusted vendor, while the facilities told victims there was "credible evidence" the stolen files had been permanently deleted and would not be published; that assurance drew scrutiny because of the long gap between the intrusion and notification and the limited transparency around the attackers and access path.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
On July 31, Bear Mountain Health and Rehabilitation, Elevate Health & Rehabilitation, and Swannanoa Valley Health and Rehabilitation notified some residents about the cybersecurity incident. The notices said stolen files had been permanently deleted and would not be published.
Three Asheville-area skilled nursing and rehabilitation entities affiliated with Ascent Healthcare Management said a threat actor logged into their systems between November 25 and November 28, 2025 and obtained files held by a trusted vendor. A Massachusetts template notice reportedly said the compromise involved credentials stolen from another unnamed trusted vendor.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
malware.news
Open sourcedatabreaches.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.