
Updated July 8, 2026:
ShinyHunters followed through on its threat. After Amazon One Medical did not enter ransom negotiations by the June 22 deadline, the group moved its data to the publication phase on its dark web leak site, claiming to have released the alleged 8.8 TB dataset. Amazon One Medical has not confirmed the scope or contents of what was actually published, and the group is known to exaggerate its claims. The company’s own investigation described the breach as limited to legacy Iora Health/One Medical Seniors patient files in a specific third-party archive — a much narrower scope than ShinyHunters alleged.
Since our June 22 article, ShinyHunters has continued targeting healthcare organizations. Most significantly, medical device giant Medtronic — the world’s largest medical device manufacturer — is now notifying more than 3.8 million individuals that their protected health information (PHI) was exposed in an April 2026 breach claimed by ShinyHunters. The ransom group’s listing of Medtronic later disappeared from its leak site, which typically suggests a ransom was paid, though Medtronic has not confirmed this. Several class action lawsuits have already been filed.
This is a developing story, and will be updated as it unfolds.
- The ransomware group ShinyHunters claims to have stolen 8.8 terabytes of data from One Medical, an Amazon subsidiary.
- One Medical operates over 250 clinics across 19 states.
- The group threatened to begin publishing the data if One Medical didn’t respond by June 22.
- One Medical asserts that only a limited number of patients were affected and is notifying those patients directly.
- At least five proposed class action lawsuits have been filed against One Medical, according to Becker’s Health IT
Healthcare today relies on digital agility, cloud integrations, and multiple-layered vendor relationships. However, this interconnected infrastructure has created a lucrative environment for sophisticated cybercriminal groups. The latest high-profile organization to be caught in the crosshairs is Amazon’s primary care subsidiary, One Medical.
Amazon is America’s largest company by revenue today. With $716.9 billion in global revenue, it topped Walmart’s $713 billion last year. While primarily known for consumer goods sales, its portfolio is diversified, with cloud and AI infrastructure, advertising, entertainment, and healthcare. By market capitalization measures, Amazon ranks 5th, behind Microsoft.
In a stark ultimatum posted on its dark web data-leak site, ShinyHunters claimed responsibility for exfiltrating a massive trove of One Medical data. It’s not known what type of data, but it presumably includes protected health information (PHI).
The group issued a final warning on June 18, setting a June 22, 2026, deadline for One Medical to respond. Failure to comply, the group warned, will trigger a massive data release “along with several annoying digital problems that’ll come your way.”
This developing situation is a reminder of the hidden risks lurking in enterprise environments. Understanding how this breach occurred, who is behind it, and what it means for compliance requires examining the histories of both the victim and the thief.
The Breach: 8.8 Terabytes Held Hostage
The scale of the alleged theft is staggering. ShinyHunters claims to have stolen 8.8 terabytes of data from One Medical. In the specialized world of healthcare data breaches, files of this magnitude could easily translate into millions of individual patient records, compromising everything from basic demographic data to detailed clinical histories. But this may not be the case.
One Medical issued a statement clarifying the cybersecurity incident, though it did not name ShinyHunters directly. According to the company’s investigation, the hack did not breach its core electronic medical record (EMR) system or Amazon’s mainstream infrastructure. Instead, unauthorized access was limited to a third-party file storage platform used to retain legacy archived information from its One Medical Senior Health division.
The timeline of the breach shows how quickly these groups operate:
- June 8 – June 11, 2026: The hackers successfully gain access to the legacy third-party file storage platform.
- June 13, 2026: One Medical discovers the unauthorized activity, immediately deactivates the affected environment, revokes user access, and begins rotating corporate credentials.
- Mid-June 2026: ShinyHunters publicly adds One Medical to its data leak site, publicizing the 8.8 TB figure and establishing the June 22 deadline.
Importantly, One Medical stated that the compromised archive contains legacy data specific to One Medical Seniors, a business unit formerly known as Iora Health. While the full extent of the compromised data types has not been disclosed, initial reviews confirm that the files contained clinical records and demographic data across several metropolitan hubs, including Atlanta, Cape Cod, Charlotte, Denver, Houston, Phoenix, Tucson, and Seattle.
The Growth and Scale of One Medical
To understand the significance of this incident, it helps to examine One Medical’s footprint in the healthcare marketplace. Founded in 2007 by Tom Lee, One Medical set out to disrupt traditional primary care by introducing a membership-based, tech-forward hybrid model that combines sleek physical clinics with 24/7 on-demand virtual health consultations.
The strategy was highly successful. One Medical expanded rapidly across major metropolitan areas, appealing directly to corporate clients seeking to offer top-tier health benefits to their employees. In 2021, to expand its reach into the Medicare and older adult demographic, One Medical acquired Iora Health for approximately $2.1 billion, rebranded the acquisition as One Medical Seniors, and inherited Iora Health’s tech stack, clinical databases, and legacy storage environments.
The turning point came in 2023, when retail and cloud giant Amazon acquired One Medical for $3.9 billion. The acquisition integrated primary care directly into the broader Amazon ecosystem, offering exclusive membership discounts to Amazon Prime subscribers and collaborations with Amazon Pharmacy.
Today, One Medical serves employees at more than 8,500 corporate clients and operates a national network of more than 250 physical clinics across the United States. Given this massive operational scale, any threat to its network naturally raises alarms about national security and consumer privacy.
Who Are the ShinyHunters?
The group behind this extortion plot is not a typical ransomware group. ShinyHunters, whose name is a nod to the rare “shiny” variants in the Pokémon video game franchise, emerged on the dark web around late 2019 and gained widespread notoriety in May 2020. It has earned a reputation as one of the most aggressive data-theft organizations.
Unlike traditional ransomware groups that primarily deploy malware to encrypt local networks and paralyze business operations, ShinyHunters primarily operates as a data extortion group. Their methodology centers on silent infiltration, rapid exfiltration of bulk data, and a strict “pay-or-leak” dark web auction structure.
Over the years, the group has claimed responsibility for some of the largest corporate data breaches in history. It has repeatedly targeted cloud misconfigurations, stolen access (OAuth) tokens, and software-as-a-service (SaaS) integrations.
A few recent examples (among dozens) from its seven-year track record highlight its reach:
Snowflake Customer Campaign 2024 Exploited stolen contractor credentials to exfiltrate massive data troves from enterprise environments, including Ticketmaster (560M records), Santander Bank(30M records), and AT&T (109M call logs).
Salesforce SaaS Campaign 2025 Used exposed access (OAuth) tokens to compromise approximately 760 connected Salesforce customer environments, resulting in the theft of roughly 1.5 billion records.
DentaQuest Breach 2026 Leaked 234 gigabytes of sensitive data from one of the largest dental benefits managers in the United States, affecting an estimated 2.6 million individuals.
Crunchbase 2026 Stole over 2 million records and published 400MB of compressed data on their dark web site when Crunchbase refused to pay a ransom.
The group’s tactical evolution has increasingly relied on sophisticated social engineering, including voice phishing (vishing) campaigns to bypass multi-factor authentication (MFA) and to target third-party vendors, thereby compromising primary targets downstream.
The Compliance Takeaway for HIPAA Entities
The immediate focus today, June 22, is whether ShinyHunters will carry out its threat to publish the 8.8 TB dataset.
However, for compliance officers, Chief Information Security Officers (CISOs), and IT infrastructure architects managing HIPAA-regulated systems, the broader lessons from this breach are clear.
Mergers, Acquisitions, and Inherited Technical Debt
The One Medical incident highlights a blind spot in corporate cybersecurity: the soft underbelly of mergers and acquisitions. When One Medical acquired Iora Health in 2021, it didn’t just acquire a patient base; it inherited years of legacy infrastructure, file structures, and data repositories.
Cybercriminals target these environments because they are rarely monitored as rigorously as active enterprise production systems. HIPAA-regulated entities must conduct exhaustive cybersecurity due diligence during acquisitions. Legacy data must either be securely migrated and mapped to core protected architectures or securely scrubbed and archived offline.
Third-Party Vendor Vulnerability
The breach occurred on a third-party file-storage platform rather than in One Medical’s internal EMR. Under the HIPAA Security Rule, a covered entity can be held strictly liable for data exposure caused by a Business Associate if it failed to exercise proper diligence. Organizations must actively monitor third-party compliance, enforce stringent Business Associate Agreements (BAAs), and ensure that external cloud storage partners use automated credential rotation, encryption at rest, and immutable logging protocols.
Strict Adherence to Administrative Safeguards
The Administrative Safeguards of the HIPAA Security Rule (§164.308) require a continuous, active security management process. This means organizations cannot treat risk analyses as annual, check-the-box compliance tasks. A truly robust posture requires continuous review of information system activity. Security teams must actively audit access to older archives, immediately de-provision dormant accounts, and tightly restrict API and OAuth integrations that connect legacy data to broader cloud ecosystems.
Final Thoughts
The ShinyHunters threat against Amazon’s One Medical underscores that data remains both a primary asset and a critical vulnerability in modern healthcare. As threat actors shift away from encrypting systems and double down on large-scale data extortion, healthcare organizations must recognize that legacy archives require the same defense-in-depth protections as active clinical networks. Leaving older data stores unmonitored is an open invitation to an expensive, high-stakes crisis.

