INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

AdaptHealth suffers massive cyberattack exposing 4.1 million people

| 2026-09-09 21:30 CRITICAL HIGH DATA BREACH
Executive Summary
AI-generated
A cyberattack attributed to the ShinyHunters threat group exposed data of 4.1 million people, including full names, contact information, demographic information, health insurance information, and health information, in a breach that occurred on June 5, 2026, at healthcare company AdaptHealth. The attackers gained access through a successful social engineering ploy that compromised the privileged account of a third-party contractor, targeting cloud-based business applications including internal patient management systems, document storage platforms, and electronic health record system portals. As of August 14, impacted individuals had already received data breach notifications with instructions on how to enroll in free-of-charge credit monitoring and identity protection services; no evidence of identity theft or misuse was found.
Technical Mitigations AI-generated
• Use multi-factor authentication for privileged accounts to prevent successful social engineering ploys. • Monitor cloud-based business applications and document storage platforms for unauthorized access or data exfiltration. • Implement robust identity protection services, such as the free-of-charge 12-month credit monitoring service offered by AdaptHealth.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
Global Scope healthhealth
Incident Timeline
‎July 2024
Threat actors, identified as ShinyHunters, used cyberattacks to target AdaptHealth's network of 680 locations across all 50 U.S. states in July 2024.
general_metric 4.1 people
general_metric 50 U.S. states
general_metric 680 locations
threat_actor ShinyHunters
organisation The HIPAA Journal
organisation the U.S. Department of Health and Human Services
organisation Aesto Health
organisation Unlimited Technology Systems
organisation BleepingComputer
organisation ShinyHunter
organisation The Blue Report 2026
‎June 5
Threat actors used social engineering tactics to target AdaptHealth's systems, resulting in the compromise of sensitive data.
industry Health
tactic Data Breach
‎June 15
An unnamed threat actor contacted AdaptHealth on June 15 to demand a ransom payment in exchange for not leaking the stolen data.
‎July 2, 2026
Threat actors used a successful social engineering ploy to compromise the privileged account of a third-party contractor, resulting in attackers accessing AdaptHealth's cloud-based business applications and exfiltrating private data.
organisation Securities and Exchange Commission
organisation SEC
‎2026/08/10
Threat actors used an unspecified method to target McKesson and Nutex Health, resulting in a data breach that exposed approximately 4.1 million people.
industry Health
tactic Data Breach
organisation McKesson
organisation Nutex Health
‎August 14
AdaptHealth confirmed that 4.1 million people were exposed to potential data breaches in a cyberattack that occurred on June 5.
industry Health
tactic Data Breach
‎2026/09/09
Threat actors attributed to the ShinyHunters group exposed data of 4.1 million people at healthcare company AdaptHealth in July.
organisation AdaptHealth
threat_actor ShinyHunters
Intelligence Sources