Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [incident, healthcare, breach, adapthealth, shinyhunters, third-party] ยท confidence: high ยท severity: critical ยท affected_sectors: [healthcare] ยท au_impact: false

Medical-supply company AdaptHealth โ€” a US home-medical-device provider covering respiratory, sleep-apnoea and mobility products across all 50 states โ€” confirmed that data of 4,115,802 individuals was exposed in a cyberattack first disclosed to the SEC on 2 July 2026 and attributed to the ShinyHunters threat group. The breach surfaced through a social-engineering ploy that compromised the privileged account of a third-party contractor, with access to cloud-based patient-management systems, document storage and electronic-health-record portals. Exposed data includes names, contact and demographic information, and health-insurance and health information. AdaptHealth filed the exposure with HHS's Office for Civil Rights, is notifying affected individuals with 12 months of free credit monitoring, and said it found no evidence the stolen data had been misused.

Attribute Detail
Date Confirmed 2026-09-09 (breach Junโ€“Jul 2026)
Affected 4,115,802 individuals
Type Data breach via third-party contractor credential compromise
Actor ShinyHunters (attributed)
Breach label Confirmed breach
Source BleepingComputer / HHS OCR โ€” Tier 2/1

Source