INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
AdaptHealth suffers massive cyberattack exposing 4.1 million people
| 2026-09-09 21:30 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
A cyberattack attributed to the ShinyHunters threat group exposed data of 4.1 million people, including full names, contact information, demographic information, health insurance information, and health information, in a breach that occurred on June 5, 2026, at healthcare company AdaptHealth. The attackers gained access through a successful social engineering ploy that compromised the privileged account of a third-party contractor, targeting cloud-based business applications including internal patient management systems, document storage platforms, and electronic health record system portals. As of August 14, impacted individuals had already received data breach notifications with instructions on how to enroll in free-of-charge credit monitoring and identity protection services; no evidence of identity theft or misuse was found.
Technical Mitigations AI-generated
• Use multi-factor authentication for privileged accounts to prevent successful social engineering ploys.
• Monitor cloud-based business applications and document storage platforms for unauthorized access or data exfiltration.
• Implement robust identity protection services, such as the free-of-charge 12-month credit monitoring service offered by AdaptHealth.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
Global Scope
healthhealth
Incident Timeline
July 2024
Threat actors, identified as ShinyHunters, used cyberattacks to target AdaptHealth's network of 680 locations across all 50 U.S. states in July 2024.
Click on any entity below to view its context and source!
general_metric
4.1 people
According to information on the company’s website, AdaptHealth served
about 4.1 million patients
across all 50 U.S. states through a network of 680 locations as of July 2024.
general_metric
50 U.S. states
According to information on the company’s website, AdaptHealth served
about 4.1 million patients
across all 50 U.S. states through a network of 680 locations as of July 2024.
general_metric
680 locations
According to information on the company’s website, AdaptHealth served
about 4.1 million patients
across all 50 U.S. states through a network of 680 locations as of July 2024.
threat_actor
ShinyHunters
The HIPAA Journal
previously reported
that ShinyHunters was responsible for the attack, based on the threat actor adding the company to the list of victims.
organisation
The HIPAA Journal
The HIPAA Journal
previously reported
that ShinyHunters was responsible for the attack, based on the threat actor adding the company to the list of victims.
organisation
the U.S. Department of Health and Human Services
In a submission to the U.S. Department of Health and Human Services, the
AdaptHealth data breach affects 4,115,802
individuals.
organisation
Aesto Health
AdaptHealth's confirmation of the data breach impact follows similar recent disclosures from health-tech firms
Aesto Health
,
CareCloud
, and
Unlimited Technology Systems
.
organisation
Unlimited Technology Systems
AdaptHealth's confirmation of the data breach impact follows similar recent disclosures from health-tech firms
Aesto Health
,
CareCloud
, and
Unlimited Technology Systems
.
organisation
BleepingComputer
However, BleepingComputer coould not find an AdaptHealth entry on ShinyHunter's extortion portal, an indication that the threat actor removed the company.
organisation
ShinyHunter
However, BleepingComputer coould not find an AdaptHealth entry on ShinyHunter's extortion portal, an indication that the threat actor removed the company.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
June 5
Threat actors used social engineering tactics to target AdaptHealth's systems, resulting in the compromise of sensitive data.
Click on any entity below to view its context and source!
industry
Health
In an
update
on August 14, AdaptHealth informed that the compromise had occurred on June 5 and may have exposed the following data:
Full names
Contact information
Demographic information
Health insurance information
Health information
Impacted individuals should have already received a data breach notification with instructions on how to enroll in a free-of-charge 12-month credit monitoring and identity protection service.
tactic
Data Breach
In an
update
on August 14, AdaptHealth informed that the compromise had occurred on June 5 and may have exposed the following data:
Full names
Contact information
Demographic information
Health insurance information
Health information
Impacted individuals should have already received a data breach notification with instructions on how to enroll in a free-of-charge 12-month credit monitoring and identity protection service.
June 15
An unnamed threat actor contacted AdaptHealth on June 15 to demand a ransom payment in exchange for not leaking the stolen data.
July 2, 2026
Threat actors used a successful social engineering ploy to compromise the privileged account of a third-party contractor, resulting in attackers accessing AdaptHealth's cloud-based business applications and exfiltrating private data.
Click on any entity below to view its context and source!
organisation
Securities and Exchange Commission
AdaptHealth first disclosed the incident in a
filing
with the U.S. Securities and Exchange Commission (SEC) on July 2, 2026, informing that attackers accessed its systems and exfiltrated private data.
organisation
SEC
AdaptHealth first disclosed the incident in a
filing
with the U.S. Securities and Exchange Commission (SEC) on July 2, 2026, informing that attackers accessed its systems and exfiltrated private data.
2026/08/10
Threat actors used an unspecified method to target McKesson and Nutex Health, resulting in a data breach that exposed approximately 4.1 million people.
Click on any entity below to view its context and source!
industry
Health
McKesson
and
Nutex Health
also disclosed data breach incidents late last month, but neither has determined the number of impacted individuals yet.
tactic
Data Breach
McKesson
and
Nutex Health
also disclosed data breach incidents late last month, but neither has determined the number of impacted individuals yet.
organisation
McKesson
McKesson
and
Nutex Health
also disclosed data breach incidents late last month, but neither has determined the number of impacted individuals yet.
organisation
Nutex Health
McKesson
and
Nutex Health
also disclosed data breach incidents late last month, but neither has determined the number of impacted individuals yet.
August 14
AdaptHealth confirmed that 4.1 million people were exposed to potential data breaches in a cyberattack that occurred on June 5.
Click on any entity below to view its context and source!
industry
Health
In an
update
on August 14, AdaptHealth informed that the compromise had occurred on June 5 and may have exposed the following data:
Full names
Contact information
Demographic information
Health insurance information
Health information
Impacted individuals should have already received a data breach notification with instructions on how to enroll in a free-of-charge 12-month credit monitoring and identity protection service.
tactic
Data Breach
In an
update
on August 14, AdaptHealth informed that the compromise had occurred on June 5 and may have exposed the following data:
Full names
Contact information
Demographic information
Health insurance information
Health information
Impacted individuals should have already received a data breach notification with instructions on how to enroll in a free-of-charge 12-month credit monitoring and identity protection service.
2026/09/09
Threat actors attributed to the ShinyHunters group exposed data of 4.1 million people at healthcare company AdaptHealth in July.
Click on any entity below to view its context and source!
organisation
AdaptHealth
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group.
threat_actor
ShinyHunters
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group.
Intelligence Sources
BleepingComputer
2026-09-09
AdaptHealth confirms 4.1 million people exposed in July cyberattack
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:55
Comprehensive Tactical Telemetry
Highly Correlated Entities
12x
organisation
Identified Entity
AdaptHealth
entity
7x
timeline
Temporal Reference
August 14
date
3x
industry
Targeted Sector
Healthcare
sector
3x
tactic
Cyber Operation Type
Data Breach
tactic
Contextual Telemetry
Context Block
7 METRICS
threat actor
APT Group
ShinyHunters
actor
general metric
People
4,100,000
people
general metric
Individuals
4,115,802
individuals
general metric
U.S. States
50
u.s. states
general metric
Locations
680
locations
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.