ShinyHunters Leaks 7.1 Million Baxter International Records

The ShinyHunters data theft and extortion group recently claimed responsibility for an intrusion at the medical device manufacturer Baxter International (Baxter). Baxter was added to its dark web data leak site a day after Baxter issued a statement about a cybersecurity incident. ShinyHunters proceeded to leak around 7.1 million records allegedly stolen in the incident. The data leak suggests that Baxter refused to negotiate payment or that negotiations broke down.

Baxter is a Deerfield, Illinois-based manufacturer of medical devices for renal care, IV solutions & infusion pumps, surgical products, inhaled anesthetics, and a range of patient monitoring devices and digital health tools. According to an August 13, 2026, statement from Baxter, unauthorized activity was detected within certain third-party applications. The company immediately activated its cybersecurity response procedures and launched an investigation, with assistance provided by third-party cybersecurity and digital forensics experts. The investigation is ongoing to determine the types and amount of information that may have been accessed or acquired.

Baxter said the incident did not have any impact on patient services or business continuity, and the company continues to operate normally. The incident has not had any impact on its products, connected solutions, or technologies used by customers to deliver patient care. Baxter said it does not anticipate the incident having a material impact on financials or the results of operations. The name of the threat group behind the incident was not publicly disclosed.

On August 14, 2026, ShinyHunters added an entry to its dark web data leak site claiming responsibility for the attack. ShinyHunters gave Baxter an August 17, 2026, deadline to negotiate payment, and threatened to leak the stolen data if payment was not made. On August 19, 2026, ShinyHunters released the stolen data for download.

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

Baxter has not confirmed the nature of the stolen data, only stating that the attack involved certain third-party applications. ShinyHunters claims that 7.1 million Salesforce records were exfiltrated in the attack, some of which contained personally identifiable information. While the group claims to have obtained 7.1 million records, that does not necessarily mean that 7.1 million patients have been affected. Baxter said it will provide updates as appropriate as additional information is confirmed.

ShinyHunters is one of the most active data theft and extortion groups. The group targets large organizations and has claimed several healthcare victims. In June 2026, ShinyHunters claimed to have exfiltrated 8.8 terabytes of data from Amazon-owned OneMedical, including the protected health information of 153,000 patients. Also in June, the group claimed to have exfiltrated 234 GB of data from DentaQuest, including the protected health information of approximately 2.6 million individuals. ShinyHunters was also behind an incident at another medical device manufacturer earlier this year. In July, Medtronic confirmed that the protected health information of 3.8 million patients was stolen in the attack. Other healthcare victims include iRhythm, AdaptHealth, and Him & Hers.

ShinyHunters has targeted companies across a range of different sectors, and while the group’s attacks appear to be opportunistic, the list of victims includes many healthcare organizations. The increasing number of attacks on healthcare organizations prompted Health-ISAC to issue an alert to the healthcare and public health sector in July about the ShinyHunters group.

The post ShinyHunters Leaks 7.1 Million Baxter International Records appeared first on The HIPAA Journal.

Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam

More than a dozen U.S. health care systems have issued warnings to patients about an ongoing phishing campaign involving emails purporting to be legitimate communications sent via their MyChart patient portal. Many of the emails claim that the recipient is a winner of a MyChart Medicare Kit, although other healthcare benefits, Medicare packages, free gifts, or rewards may be offered. Texas Health Resources has warned patients that some email communications offered a “Senior Health Package.”

Healthcare providers that use Epic Systems’ electronic health records and MyChart portals, including Methodist Health System, Premier Health, Sentara Health, Metro Health, and Texas Health Resources, have added scam warnings to their websites about the campaign. The scammer most likely seeks MyChart credentials, Medicare information, financial account information, or other sensitive data.

The emails are not sent from legitimate healthcare provider email addresses or domains, and while they include a MyChart logo, they have not been sent by Epic Systems. The logo is used to make the messages appear legitimate. An example of one of the phishing emails is detailed below, although other messages may also be used in this campaign.

Epic Systems MyChart phishing scam

Example of a phishing email impersonating MyChart

“We’ve seen an uptick in scammers trying to trick patients by using the MyChart name or logo to make emails, text messages, phone calls, and websites look official,” explained Trevor Berceau, Director R&D, Epic Systems. “Some might try to steal your login information or promise free gifts if you enter payment details. The increase in attempts is due to scammers taking advantage of the popularity of the MyChart brand rather than any security concern, so you can continue to use MyChart as normal. If something doesn’t feel right, however, stop and check.”

Get The FREE
HIPAA Compliance Checklist

Immediate Delivery of Checklist Link To Your Email Address

Please Enter Correct Email Address

Your Privacy Respected

HIPAA Journal Privacy Policy

The threat actor behind the campaign has yet to be identified, and it is unclear how the cybercriminal or group behind the scam obtained patients’ contact information. It is likely that email addresses were obtained in a previous data breach, although that data breach may not necessarily have occurred at their healthcare provider.

The advice to patients is to delete any such messages immediately and not click on any links, including the “unsubscribe” link. It is important not to reply to the email, and to never disclose personal or financial information in response to one of these communications or attempt to log in to the patient portal using the link in the message. If any action has been taken, such as logging in via the link, patients should immediately reset their MyChart portal password and contact their healthcare provider’s MyChart support team.

Patients should remain vigilant against any unsolicited emails, text messages, or phone calls claiming to offer free gifts or rewards. Recipients of emails or text messages should carefully check the sender’s information to ensure that it has come from a legitimate email address or domain. These messages often include spelling and grammatical errors, unusual requests, free gifts or rewards, and often advise the recipient to take immediate action. If in any doubt about the legitimacy of any request, patients should contact the relevant healthcare provider using verified contact information. Never use any contact information included in the suspicious communication.

The post Health Systems Warn Patients About Epic MyChart Patient Portal Phishing Scam appeared first on The HIPAA Journal.