Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: healthcare (17 articles)Clear

AdaptHealth breach tied to ShinyHunters exposes health data of 4.1 million

AdaptHealth, a US network of more than 680 medical-equipment facilities, confirmed that a breach attributed to the ShinyHunters group exposed the personal, health, and insurance information of about 4.1 million people. The attackers got in by socially engineering a third-party contractor's privileged account, then reached AdaptHealth's cloud business applications, patient-management systems, and electronic health record portals, and stole a password file tied to insurance billing. It fits ShinyHunters' pattern of tricking a person into handing over access to connected cloud services, and it is the latest in a wave of large healthcare breaches this year alongside Aesto, CareCloud, and McKesson. Social security and financial data were reportedly not taken.

Check
Affected patients should watch for medical, insurance, and identity fraud and use the offered monitoring, and healthcare organizations should tighten third-party and contractor account access against social engineering.
Affected
About 4.1 million people whose names, contact details, and health and insurance information were exposed; the data supports targeted phishing and insurance fraud, and the contractor-account entry shows the third-party path.
Fix
Require phishing-resistant authentication and least privilege for contractors and third parties, monitor connected cloud apps for anomalous access, verify help-desk and account changes, and treat contractor accounts as a primary attack surface.

Aesto Health breach exposes health and identity data of 9.5 million people

Aesto Health, a healthcare technology company that handles data migration, records exchange, and archiving for medical providers, disclosed that a breach of its Amazon Web Services infrastructure exposed the personal and health information of more than 9.5 million people. Attackers accessed the environment in December 2025, and the company later confirmed they took names, Social Security and driver's license numbers, dates of birth, financial account numbers, and detailed medical and insurance information. Because Aesto is a vendor serving many providers, the single breach cascades to roughly two dozen healthcare clients. It is the second-largest confirmed US healthcare breach reported this year, and the data enables identity theft and targeted fraud.

Check
If you are a provider using Aesto Health or a patient of one, watch for breach notifications, monitor medical, insurance, and financial statements, and treat health-themed phishing referencing real details with suspicion.
Affected
More than 9.5 million patients across about two dozen providers served by Aesto Health; exposed names, Social Security numbers, financial accounts, and medical records support identity theft, insurance fraud, and targeted phishing.
Fix
Affected people should monitor accounts and consider credit protection; organizations should secure cloud infrastructure, minimize retained data, encrypt records, and vet the security of data-handling vendors whose breach would cascade.

McKesson discloses breach as ShinyHunters claims 284 million patient records

Healthcare and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, which the extortion group ShinyHunters claims exposed 284 million patient records. The group told reporters it broke in by voice-phishing two employees, then extracted data from the company's Salesforce and Snowflake environments, the same connected-app looting pattern it has used elsewhere. It claims deeply sensitive medical data was taken and says a roughly 55 million dollar ransom went unanswered. McKesson confirmed the incident in a regulatory filing but has not verified what was stolen, and the record count, like past ShinyHunters claims, may be inflated.

Check
Watch McKesson's official channels for confirmed details before acting on the 284 million figure, and if notified as affected, be alert to healthcare-themed phishing and identity theft using real medical details.
Affected
Patients and partners whose data McKesson handles, pending confirmation of scope; ShinyHunters claims names, Social Security numbers, and sensitive medical records were taken via phished access to Salesforce and Snowflake.
Fix
For organizations, harden connected SaaS like Salesforce and Snowflake against voice-phishing-led access with phishing-resistant authentication and tighter session controls, and verify large breach claims before treating headline numbers as confirmed.

Exact Sciences breach exposes data of nearly 11 million in extortion campaign

Data from a breach at cancer-screening company Exact Sciences, now part of Abbott, was indexed by Have I Been Pwned with about 10.9 million unique email addresses. The extortion group ShinyHunters claimed the intrusion, saying it reached internal legacy systems and then pivoted from a corporate single-sign-on account into connected cloud services such as Microsoft 365, Salesforce, and others to steal data. It is part of a wider ShinyHunters wave hitting medical-technology companies. Abbott is investigating and disputed the attacker's characterization of some data. The pattern, one stolen sign-on unlocking many linked services, is now a recurring route to large healthcare breaches.

Check
People who used Exact Sciences services should watch for breach notices and health-themed phishing, and organizations should map which cloud services a single corporate sign-on can unlock.
Affected
Roughly 11 million people whose data sat in Exact Sciences systems and connected cloud services; attackers used one corporate sign-on to reach linked platforms, a pattern behind repeated large medical breaches.
Fix
Enforce phishing-resistant MFA on single-sign-on, scope what each connected cloud app can access, monitor for bulk exports across integrated services, and prepare for extortion-driven leaks of healthcare data.

Amgen says patient health and research data stolen from third-party cloud systems

Biotechnology company Amgen disclosed that attackers stole patient and corporate data from multiple cloud systems run by third-party providers, rather than from its own servers. In a securities filing, Amgen said it detected the intrusion in July, confirmed data was exfiltrated, and determined the incident material based on the volume and sensitivity of affected files. Confirmed stolen data includes proprietary company information and patient protected health information, and the company is still assessing whether intellectual property, research and development data, and further patient records were taken. Operations, product supply, and financial systems were not disrupted. Amgen has not named a provider, entry point, or responsible party.

Check
Organizations relying on third-party cloud providers should confirm what sensitive data those providers hold, how it is protected, and whether breach notification and monitoring obligations are covered in contracts.
Affected
Amgen patients and partners whose protected health information and proprietary data sat in third-party cloud environments; intellectual property and research data may also be affected, deepening the impact beyond ordinary personal information.
Fix
Minimize and segment sensitive data held by vendors, require strong access controls and logging on third-party cloud environments, monitor for bulk exfiltration, and prepare for extortion and phishing after healthcare breaches.

DentaQuest notifies more than 23 million people after a data theft attack

Dental benefits administrator DentaQuest, part of Sun Life, is notifying more than 23 million people that their personal and health information was stolen in a May 2026 network intrusion. The company found unauthorized access on May 20 and determined attackers were in its network between May 17 and 20. Exposed data includes names, addresses, Social Security numbers, member, Medicaid, and Medicare identifiers, and dental and vision health details such as diagnoses, treatments, and billing. The extortion group ShinyHunters claimed responsibility and leaked roughly 234GB. DentaQuest has confirmed at least 15 million affected, with independent analysis putting the figure above 23 million, and is offering two years of monitoring.

Check
People with DentaQuest or associated Medicaid or Medicare dental coverage should watch for a notification, enroll in the offered monitoring, consider a credit freeze, and be alert to health-themed phishing.
Affected
More than 23 million DentaQuest members whose names, Social Security numbers, government program identifiers, and dental and vision health records were exposed and leaked, supporting identity theft and targeted fraud.
Fix
Affected people should freeze credit and monitor benefits statements. Organizations holding health data should segment it, enforce phishing-resistant MFA, monitor for bulk data access, and prepare for extortion-driven leaks.

Medtronic breach notifications reach 3.8 million people with SSNs and health data exposed

Medtronic has begun notifying about 3.8 million people that their data was exposed in the breach of its corporate IT systems earlier this year, giving a concrete scale to the ShinyHunters attack it first disclosed in April. The exposed information includes names, contact details, dates of birth, Social Security numbers, and health-related data, a more sensitive set than the company initially detailed. The intrusion, which the extortion group claimed involved around nine million records, was limited to corporate systems, with Medtronic saying its products, patient safety, and device networks were not affected. Affected individuals are being offered credit monitoring, and several class-action lawsuits have followed.

Check
People who have been customers, patients, or partners of Medtronic should watch for a notification letter, take up any offered credit monitoring, and stay alert to phishing that references Medtronic.
Affected
About 3.8 million individuals whose names, contact details, dates of birth, Social Security numbers, and health information were exposed in Medtronic's corporate IT breach; device networks and patient safety were not affected.
Fix
Affected people should enroll in the offered monitoring, consider a credit freeze given the exposed Social Security numbers, and treat medical-themed phishing with caution. Organizations should segment corporate IT from clinical systems.

Medtronic notifies customers after ShinyHunters breach of corporate systems

Medical device maker Medtronic has begun notifying customers that their personal data was exposed in a breach of its corporate IT systems earlier this year, an attack claimed by the extortion group ShinyHunters. Medtronic noticed unusual activity in mid-April and its investigation found that an unauthorized actor had access between April 13 and 19. ShinyHunters claimed to hold roughly nine million records containing personal and internal corporate data, and Medtronic did not pay, with its listing later removed from the group's leak site. The company says its products, patient safety, and the networks running its medical devices were not affected, crediting separation between corporate and clinical systems.

Check
People who have dealt with Medtronic as customers, patients, providers, or partners should watch for their notification and stay alert to phishing or fraud that references Medtronic or medical accounts.
Affected
Individuals whose personal data sat in Medtronic's corporate IT systems, accessed between April 13 and 19; ShinyHunters claimed about nine million records, though device networks and patient safety were not affected.
Fix
Affected people should monitor for targeted phishing and identity fraud. Organizations should segment corporate IT from operational and clinical systems, harden SaaS and identity against social engineering, and enforce phishing-resistant MFA.

Healthcare AI vendor Xsolis breach exposes data on 1.4 million people

Xsolis, a US healthcare technology company whose AI software is used by more than 600 hospitals and insurers for utilization management and reimbursement decisions, has disclosed a breach affecting 1,396,519 people. Attackers got in through a targeted phishing attack on an employee in January, accessing files containing patient data Xsolis handles for its clients. The exposed information includes names, dates of birth, addresses, Social Security numbers, health insurance details, and medical treatment information. Because Xsolis is a vendor, affected individuals may never have dealt with it directly; downstream health systems including Mayo Clinic are among those whose patients are impacted.

Check
Healthcare organizations should check whether they share data with Xsolis and confirm their breach-notification obligations; affected individuals should watch for medical, insurance, and identity fraud and any Xsolis-related notice.
Affected
Patients and health-plan members whose data Xsolis processed for hospitals and insurers (1,396,519 affected); exposed Social Security numbers and medical information carry lasting identity-theft and medical-fraud risk.
Fix
Affected people should enroll in the offered monitoring, freeze credit, and watch insurance statements. Healthcare organizations should strengthen phishing-resistant MFA, map which vendors hold patient data, and tighten access to health-data repositories.

Cardiac monitoring firm iRhythm says patient health data stolen in attack

iRhythm, the US digital-health company behind the Zio wearable heart monitor, has told regulators that attackers stole patient data in a breach it considers material. In an SEC filing, the company said it detected unauthorized activity on June 8 in third-party-hosted business applications, accessed through a social-engineering attack, and received an extortion demand the next day from a threat actor claiming to hold proprietary data, protected health information, and other personal data. iRhythm says its clinical systems, medical devices, patient safety, and operations were not affected, with no payment-card or financial data involved. No ransomware group has publicly claimed the attack, and the number of affected people is not yet known.

Check
Healthcare and other organizations should review how third-party-hosted business applications are secured and monitored, and confirm that help desks and staff can resist social-engineering attempts to grant access.
Affected
iRhythm patients and others whose protected health information and personal data sat in the affected third-party business applications; clinical systems, devices, and financial data were reportedly not involved.
Fix
Enforce phishing-resistant MFA and strong identity verification on third-party SaaS, limit and log access to systems holding health data, and rehearse social-engineering scenarios with staff and help-desk teams.