A ransomware attack on a Spring-based ambulance company exposed Social Security numbers, medical records and other sensitive data for 14,324 Texans.
City Ambulance Service, headquartered at 7007 Wimbledon Estates Dr., disclosed the breach to the Texas Attorney General's office on Sept. 1, according to a ClaimDepot investigation page citing the state filing. The exposed information includes names, addresses, Social Security numbers, dates of birth, medical information and health insurance details.
The ransomware group Qilin claimed responsibility for the attack on July 19, posting on the dark web that it had obtained sensitive data and planned to publish it within days. Qilin uses what cybersecurity researchers call "double extortion," stealing data and threatening to release it unless a ransom is paid. Cybernews reported the group has claimed roughly 1,900 victims over the past 18 months.
City Ambulance Service, operated by Viking Enterprises, Inc., provides ground medical transport for hospitals, urgent care centers, fire departments and public events. The company operates in Houston, San Antonio and Dallas and holds municipal ambulance agreements in Austin and Port Arthur.
The company has not publicly responded to the breach. It is unknown whether notification letters have been sent to affected patients, whether credit monitoring has been offered, or whether the stolen data was published.
A class-action law firm said it is investigating the breach on behalf of potentially affected individuals. No lawsuit has been filed as of Sept. 6.







