AllerVie Health: AllerVie Health Data Breach Leaks Social Security Numbers

AllerVie Health: AllerVie Health Data Breach Leaks Social Security Numbers

**AllerVie Health Hit by ANUBIS Ransomware Attack, Exposing Sensitive Patient Data**

On December 23, 2025, AllerVie Health, a prominent provider of allergy and immunology services, disclosed a data breach stemming from a ransomware attack by the ANUBIS group. The cybercriminals claimed responsibility on November 26, 2025, via a post on the Tor network, nearly a month before the company publicly acknowledged the incident.

AllerVie Health first detected the breach on November 2, 2025, determining that unauthorized actors had accessed sensitive personally identifiable information (PII) between October 24 and November 3, 2025. The compromised data included Social Security numbers, driver’s license or state ID numbers, and patient names. The ANUBIS group, known for targeting healthcare organizations, not only encrypted data but also threatened to leak stolen information unless ransom demands were met, increasing the risk of identity theft and fraud for affected individuals.

The company reported the breach to the New Hampshire Attorney General on December 23, 2025, and began notifying impacted individuals by mail. As part of its response, AllerVie Health is offering complimentary credit monitoring and identity protection services through Cyberscout, a TransUnion company. A dedicated call center has been established for affected individuals seeking further information.

Source: https://www.claimdepot.com/data-breach/allervie-health-2025

AllerVie Health cybersecurity rating report: https://www.rankiteo.com/company/allervie-health

"id": "ALL1766599463",
"linkid": "allervie-health",
"type": "Ransomware",
"date": "12/2025",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Limited number of individuals',
                        'industry': 'Allergy and Immunology Services',
                        'name': 'AllerVie Health',
                        'type': 'Healthcare Provider'}],
 'customer_advisories': 'Notification by mail, call center setup '
                        '(833-877-1419, Monday through Friday, 8 a.m. to 8 '
                        'p.m. ET)',
 'data_breach': {'data_encryption': 'Yes (ransomware encrypted data)',
                 'data_exfiltration': 'Yes (threatened to leak stolen data)',
                 'personally_identifiable_information': 'Social Security '
                                                        'numbers, driver’s '
                                                        'license/state ID '
                                                        'numbers, names',
                 'sensitivity_of_data': 'High (Social Security numbers, '
                                        'driver’s license/state ID numbers, '
                                        'names)',
                 'type_of_data_compromised': 'Personally identifiable '
                                             'information (PII)'},
 'date_detected': '2025-11-02',
 'date_publicly_disclosed': '2025-12-23',
 'description': 'AllerVie Health disclosed a significant data breach exposing '
                'personally identifiable information (PII) of a limited number '
                'of individuals due to a ransomware attack by the ANUBIS '
                'group. The attackers accessed sensitive information between '
                'Oct. 24, 2025, and Nov. 3, 2025, and threatened to leak '
                'stolen data unless ransom demands were met.',
 'impact': {'brand_reputation_impact': 'Heightened risk of identity theft and '
                                       'fraud, potential reputational damage',
            'data_compromised': 'Personally identifiable information (PII), '
                                'including Social Security numbers, driver’s '
                                'license or state ID numbers, and names',
            'identity_theft_risk': 'High'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain, data extortion',
 'ransomware': {'data_encryption': 'Yes',
                'data_exfiltration': 'Yes',
                'ransomware_strain': 'ANUBIS'},
 'recommendations': 'Sign up for free Cyberscout identity theft protection '
                    'services, monitor credit reports and financial accounts, '
                    'be alert for phishing attempts, consider placing a fraud '
                    'alert or credit freeze with major credit bureaus',
 'references': [{'date_accessed': '2025-11-26',
                 'source': 'Dark web posting by ANUBIS group'}],
 'regulatory_compliance': {'regulatory_notifications': 'Disclosed to New '
                                                       'Hampshire Attorney '
                                                       'General'},
 'response': {'communication_strategy': 'Notification to affected individuals '
                                        'by mail, call center setup for '
                                        'inquiries',
              'incident_response_plan_activated': 'Yes',
              'third_party_assistance': 'Cyberscout (TransUnion) for credit '
                                        'monitoring and identity protection '
                                        'services'},
 'threat_actor': 'ANUBIS group',
 'title': 'AllerVie Health Ransomware Attack and Data Breach',
 'type': 'Ransomware Attack'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.