Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
▣ Breach ADAPTHEALTH-SHINYH 2026-09-10

AdaptHealth: ShinyHunters Contractor Account Compromise Exposes 4.1 Million Patients

"AdaptHealth, one of the largest US providers of home medical equipment and respiratory therapy, has confirmed that a cyberattack disclosed in July 2026 exposed the personal and health data of 4,115,802 individuals…"

AdaptHealth, one of the largest US providers of home medical equipment and respiratory therapy, has confirmed that a cyberattack disclosed in July 2026 exposed the personal and health data of 4,115,802 individuals, according to the company's submission to the US Department of Health and Human Services. BleepingComputer reports the intrusion is attributed to ShinyHunters, the extortion crew behind the 2024 Snowflake and 2025 Salesforce campaigns. The entry vector was not a vulnerability: it was a successful social engineering attack against the privileged account of a third-party contractor.

What Happened

The public record begins with a Form 8-K filed with the SEC on or about July 2, 2026, in which AdaptHealth Corp. (Nasdaq: AHCO) disclosed a material cybersecurity incident involving unauthorized system access and data exfiltration.

The timeline that emerged afterwards runs earlier than the disclosure date. Per an AdaptHealth update on August 14 reported by BleepingComputer, the compromise itself occurred on June 5, 2026. On June 15, an unnamed threat actor contacted the company demanding a ransom payment in exchange for not leaking stolen data. The law firm Edelson Lechtzin, citing the 8-K and news reports, states AdaptHealth determined the incident was material on June 27, five days before filing. That gives roughly a four-week window between initial compromise and public disclosure, and ten days between extortion contact and the materiality call.

One inconsistency is worth flagging rather than smoothing over. BleepingComputer's headline and lede describe the attack as "discovered in July," while the same article's own timeline places the extortion contact on June 15 and the compromise on June 5. The most defensible reading is that the June 15 contact was the discovery trigger and July marks public disclosure, but AdaptHealth has not published a discovery date of its own. Databreachrights.com, working only from the Vermont Attorney General filing, notes explicitly that "the exact discovery date and attack method remain undisclosed," which is a fair description of what the regulator filings alone show.

Investigators found the attacker reached cloud-based business applications, including internal patient management systems, document storage platforms, and external electronic health record system portals.

What Was Taken

AdaptHealth's own notification, per BleepingComputer, lists the exposed categories as full names, contact information, demographic information, health insurance information, and health information.

Two OTHER-tier sources go further. Both safeguard.sh and the Edelson Lechtzin release state the attacker also obtained a stored password file tied to insurance billing, alongside PII and PHI. That claim does not appear in the primary-facing reporting and should be treated as reported rather than confirmed, but it is corroborated across two independent write-ups and, if accurate, materially changes the downstream risk picture: a credential file is a pivot, not just a disclosure.

Notably, Social Security numbers are not listed in AdaptHealth's disclosed categories, in contrast to the Medtronic incident, where safeguard.sh reports SSNs and dates of birth were among the exposed fields.

On the count itself, the figures are unusually consistent. The HHS submission gives 4,115,802 individuals, cited identically by BleepingComputer and UndercodeNews. AdaptHealth's own website states the company served approximately 4.1 million patients across all 50 states through 680 locations as of July 2024. In other words, the breach count and the entire patient base are effectively the same number, which suggests exposure of the full patient population rather than a subset.

Two caveats on the numbers. UndercodeNews carries a headline claiming "More Than 41 Million Patients," which its own body text contradicts with the correct 4,115,802 figure. That is a factor-of-ten headline error, not a competing estimate, and should not be cited. Separately, databreachrights.com lists "People Affected: Not Publicly Disclosed," reflecting that the Vermont state filing does not carry a national total.

Why It Matters

The state-level view shows what a single healthcare aggregator breach does to a small population. Per Vermont Daily Chronicle, AdaptHealth reported 48,090 affected Vermonters to the state Attorney General on August 14. That is roughly one in every 13 residents, and 7.5 percent of the state's population of 644,663. It is also 57 percent of every person on Vermont's entire breach list since April 17, 2026, more than the other 289 reported breaches combined, and five and a half times the next-largest entry (Medtronic, at 8,668 Vermonters). The AG's office notes these counts can rise as companies complete their determinations, so 48,090 is a floor.

The strategic point is concentration. Durable medical equipment suppliers accumulate CPAP, oxygen, mobility, and diabetes-supply records across entire states, which is why a single vendor can outweigh every other breach in a jurisdiction combined.

The incident also sits inside a visible campaign. Health-ISAC issued an alert on or around July 31, 2026 warning of increasing successful ShinyHunters attacks against the health sector, naming Medtronic, iRhythm, OneMedical, DentaQuest, AdaptHealth, and Him & Hers among recent victims. Reported scale across that set runs into the tens of millions: approximately 3.8 million notified by Medtronic against roughly 9 million records claimed by the actors (safeguard.sh), and at least 15 million at DentaQuest per Aliteq, which also reports that figure was revised down from an initial 23.4 million estimate and that roughly 234GB was leaked after DentaQuest declined to pay.

The Attack Technique

Health-ISAC describes ShinyHunters as an identity and supply chain actor rather than a ransomware operator. There is no encryption stage and typically no malware. The pattern:

  1. Voice-based social engineering (vishing) against helpdesk or IAM staff to reset a password, reset MFA, or enroll a new device.
  2. SSO dashboard pivot. With the account live, the actor logs into Okta, Microsoft Entra, or Google SSO and reads the tenant's own app catalogue, which enumerates Microsoft 365, Salesforce, Dropbox, Google Drive, SharePoint, and other connected platforms.
  3. Cloud-scale exfiltration across those SaaS and storage tiers.
  4. Extortion, with the victim notified directly and a leak-site listing used as pressure.

In AdaptHealth's case the compromised identity belonged to a third-party contractor with privileged access. Edelson Lechtzin reports that ShinyHunters added AdaptHealth to its data leak site and threatened publication absent payment. AdaptHealth has not publicly stated whether it paid.

Health-ISAC describes a comparable recent case in which the group claimed to have vished multiple employees to compromise a Microsoft Entra account, then pulled large volumes from Microsoft 365 and SharePoint. As safeguard.sh puts it: no exploit, no CVE, no zero day. A person with legitimate access was talked out of their session, and the session was sufficient.

What Organizations Should Do

Sources: AdaptHealth confirms 4.1 million people exposed in July cyberattack | Health-ISAC Warns of Increasing ShinyHunters Healthcare Data Theft... | Medtronic and AdaptHealth Breaches: Third-Party and Contractor Acce... | AdaptHealth breach exposed health records of one in 13 Vermonters -... | AdaptHealth Data Breach Exposes Health Records | AdaptHealth Data Breach Exposes More Than 41 Million Patients in Ma... | AdaptHealth Corp. Data Breach: Edelson Lechtzin LLP | DentaQuest Data Breach 2026: ShinyHunters Leak 15 Million Records ·...