AdaptHealth breach tied to ShinyHunters exposes health data of 4.1 million
AdaptHealth, a US network of more than 680 medical-equipment facilities, confirmed that a breach attributed to the ShinyHunters group exposed the personal, health, and insurance information of about 4.1 million people. The attackers got in by socially engineering a third-party contractor's privileged account, then reached AdaptHealth's cloud business applications, patient-management systems, and electronic health record portals, and stole a password file tied to insurance billing. It fits ShinyHunters' pattern of tricking a person into handing over access to connected cloud services, and it is the latest in a wave of large healthcare breaches this year alongside Aesto, CareCloud, and McKesson. Social security and financial data were reportedly not taken.
- Check
- Affected patients should watch for medical, insurance, and identity fraud and use the offered monitoring, and healthcare organizations should tighten third-party and contractor account access against social engineering.
- Affected
- About 4.1 million people whose names, contact details, and health and insurance information were exposed; the data supports targeted phishing and insurance fraud, and the contractor-account entry shows the third-party path.
- Fix
- Require phishing-resistant authentication and least privilege for contractors and third parties, monitor connected cloud apps for anomalous access, verify help-desk and account changes, and treat contractor accounts as a primary attack surface.