
August 28, 2026 Update: McKesson, a healthcare and pharmaceutical distribution company, disclosed a cybersecurity incident affecting 284 million patient records, and ShinyHunters has claimed responsibility for the attack.
Ransomware group ShinyHunters has claimed another healthcare victim.
On August 14, 2026, the group listed medical products maker Baxter International on its dark web leak site and claimed it had stolen 7.1 million records from the company’s Salesforce platform, including personally identifiable information. One week later, when Baxter did not meet the deadline, ShinyHunters followed through on its threat, posting on August 21 that it had leaked the data and accusing the company of failing to negotiate “despite our incredible patience.”
As of this writing, Baxter has not publicly confirmed the breach, and no regulator has verified the group’s claims. However, that pattern, an unverified leak-site listing followed by a public data dump when demands go unmet, has become ShinyHunters’ signature move. Healthcare organizations have increasingly found themselves on the receiving end of this tactic.
We first covered this group in June, when it targeted Amazon One Medical. Baxter is only the latest in a string of healthcare attacks the group has carried out this year.
If your organization handles patient data or works with vendors that do, it’s worth understanding who ShinyHunters is, how it operates, and why healthcare has become such a frequent target.
Who Is ShinyHunters?
ShinyHunters first emerged in 2020 as a financially motivated data extortion group. Rather than encrypting systems like traditional ransomware gangs, ShinyHunters typically steals data from cloud and SaaS platforms and threatens to publish it unless the victim pays. Its favored targets include enterprise Salesforce, Snowflake, and Okta environments, and its methods increasingly involve voice phishing (vishing) campaigns in which attackers impersonate IT help desk staff to trick employees into handing over single sign-on credentials and multifactor authentication codes on convincing fake login pages.
Once inside, the group has been known to abuse stolen open authorization (OAuth) tokens from connected third-party applications, such as Salesloft Drift, and Gainsight, to reach Salesforce data across many downstream organizations at once. This approach has allowed ShinyHunters to compromise hundreds of organizations through a single supply-chain weakness, rather than attacking each entity individually. Security researchers have linked the group to over a hundred confirmed incidents in 2026 alone, spanning finance, retail, education, insurance, and healthcare.
Law enforcement has had some success disrupting the group. Authorities arrested four alleged members in France in June 2025. But the arrests did little to slow the group’s activity; new campaigns were already running again by early 2026, evidence that decentralized extortion networks like this one don’t necessarily stop operating just because some participants are taken off the board.
In late July, Health-ISAC, a cybersecurity information-sharing organization for the health sector, warned about ShinyHunters’ increasing focus on healthcare.
A Pattern of Healthcare Targets
Baxter is far from an isolated incident. ShinyHunters has built a lengthy healthcare track record this year alone:
- DentaQuest (June 2026). One of the largest dental and vision benefits administrators in the U.S., DentaQuest was hit early in the group’s healthcare campaign. ShinyHunters claimed to have published 234 gigabytes of data affecting 2.6 million people. When DentaQuest, a unit of Sun Life Financial, formally reported the incident to federal regulators in July, the disclosed scope grew significantly: 15 million people affected, making it by far the largest health data breach reported so far in 2026.
- Amazon One Medical (June 2026). As we covered in our earlier post, ShinyHunters claimed to have exfiltrated a massive volume of data, reported at roughly 8.8 terabytes, from the primary care provider’s systems.
- Medtronic (2026). The medical device maker was reportedly hit for approximately 9 million records as part of the same vishing-driven Salesforce campaign affecting multiple large enterprises. For a device manufacturer, stolen records can include more than contact information, but medical information as well, raising the stakes.
- NAIC (June 2026). The National Association of Insurance Commissioners, the standard-setting body serving insurance regulators nationwide, confirmed unauthorized access to its systems on June 11, 2026, tracing the intrusion to the same Salesforce-focused campaign.
- AdaptHealth (June 2026). A different flavor of the same playbook: attackers social-engineered a third-party contractor’s credentials, then used them to reach AdaptHealth’s cloud-based patient management systems, document storage, and external EHR portals. Stolen data reportedly included PII, PHI, and a stored password file tied to insurance billing. AdaptHealth disclosed the incident to the SEC as a material cybersecurity event, and ShinyHunters later added the company to its leak site, a reminder that the weak link doesn’t have to be inside your own organization.
- Abbott Laboratories / Exact Sciences (July 2026). ShinyHunters used vishing against employees to compromise legacy systems from Abbott’s recently acquired cancer diagnostics business, claiming a haul of roughly 30 million records, including a million Social Security numbers and 22 million doctor-patient notes. After an extended negotiation deadline passed unresolved, ShinyHunters published data affecting 10.9 million people, including names, contact details, dates of birth, and health information. The breach has already drawn at least one proposed class-action lawsuit.
- Baxter International (August 2026). Claimed 7.1 million records, including personally identifiable information taken from the company’s Salesforce environment.
- McKesson (August 2026). The most recent incident involved 284 million patient records and used “voice phishing, or vishing, social engineering attacks against multiple McKesson employees.”
Beyond healthcare, ShinyHunters’ 2026 victim list spans dozens of major organizations, underscoring that the group isn’t focused on a single industry. Healthcare organizations are proving to be lucrative and vulnerable targets alongside everyone else.
Why Healthcare Keeps Showing Up on the List
Healthcare organizations, and the vendors and platforms that serve them, are attractive targets for a few consistent reasons. Patient data carries a high resale and extortion value because it’s difficult to change (unlike a password) and often includes information useful for identity theft or insurance fraud. Many healthcare entities and their business associates also rely heavily on third-party SaaS platforms like Salesforce for patient relationship management, billing, and case management, which means a single compromised vendor integration can expose data across many organizations that never directly interacted with the attacker.
It’s also worth noting that ShinyHunters’ primary attack vector, vishing against help desk and IT support staff, targets human decision-making rather than a technical vulnerability. No firewall or encryption standard stops an employee who’s convinced they’re talking to their own IT department. That makes workforce training and verification procedures just as important as any technical control.
What Covered Entities and Business Associates Should Do
Whether or not your organization uses the exact platforms named above, the ShinyHunters pattern points to a few concrete steps worth taking now:
- Scrutinize third-party SaaS and OAuth integrations. Review which connected applications have access to your Salesforce, Okta, or other cloud platforms, and remove any you don’t actively need.
- Harden help desk verification procedures. Since vishing targets IT support staff directly, ensure your help desk has a strict, non-negotiable process for verifying identity before resetting credentials or enrolling MFA.
- Review vendor risk and BAAs. If a vendor holding your organization’s PHI experiences a breach through a platform like Salesforce, your organization may still bear reporting obligations. Confirm your business associate agreements clearly define breach notification responsibilities and timelines.
- Watch for downstream exposure. Even organizations that don’t use the specific platforms targeted in a given campaign should check whether any of their vendors do, since ShinyHunters’ supply-chain approach means indirect exposure is common.
ShinyHunters shows no sign of slowing down, and healthcare’s heavy reliance on interconnected cloud platforms makes it a durable target. The HIPAA E-Tool® will continue tracking developments in this campaign and others like it, and what they mean for covered entities and business associates working to stay ahead of the next headline.

