ON July 31, several facilities in Asheville, NC, notified residents of a data breach caused by a threat actor who accessed their systems from November 25-28, 2025, acquiring files from a trusted vendor, which remains unnamed. The compromised data included personal identifiers and health information. The delay in notification from November to July raises concerns about transparency.
Despite assurances that stolen files were permanently deleted, the credibility of this claim is questioned due to typical behaviors of threat actors. The three facilities reported a varying number of affected residents: Bear Mountain (1,397), Elevate (1,551), and Swannanoa (1,045). Key unanswered questions include the identity of the trusted vendor, existence of a business associate agreement, the nature of the threat actor, and details of the evidence supporting the claim of data deletion.