What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
Dark Reading editors discuss whether ShinyHunters breached ReliaQuest and new research questioning the prevalence of AI-generated malware.
Dark Reading editors review stories they had not previously covered in a video discussion, centered on recent activity attributed to the ShinyHunters threat actor and whether it constitutes a breach of security services firm ReliaQuest. The conversation also touches on new research about how common AI-generated malware actually is. No new indicators, victims, or technical details are provided beyond the discussion format.
McKesson confirms cyber incident after ShinyHunters claims patient-data theft
Healthcare giant McKesson confirmed a cyber incident after ShinyHunters claimed theft of hundreds of millions of patient records.
McKesson acknowledged a data breach following public claims by the threat actor group ShinyHunters that it stole hundreds of millions of records containing patient data. The company confirmed a cyber incident occurred but the full scope of the theft has not yet been independently verified. ShinyHunters is known for large-scale data theft and extortion against major organizations. The healthcare sector remains a frequent target for data-theft extortion groups.
ReliaQuest Rejects Compromise Claims After ShinyHunters Incident
ReliaQuest detailed a ShinyHunters-linked social engineering attack and denied reports that the threat actor successfully compromised its systems.
Cybersecurity services firm ReliaQuest disclosed a social engineering attack attributed to activity linked to the ShinyHunters group. The company denied reports that the threat actor successfully compromised its systems, stating the incident did not result in a breach.
AdaptHealth confirms 4.1 million people exposed in July cyberattack
AdaptHealth confirmed a ShinyHunters-attributed cyberattack exposed data of 4.1 million patients via a compromised third-party contractor account.
Healthcare company AdaptHealth confirmed 4,115,802 individuals were exposed in an intrusion first disclosed in an SEC filing on July 2, 2026, with the compromise beginning June 5. Attackers used social engineering to compromise a privileged third-party contractor account, accessed cloud-based patient management, document storage and EHR portals, and exfiltrated names, contact details, demographic, insurance and health information before a June 15 ransom demand. The attack was attributed to the ShinyHunters group, though the company no longer appears on the gang's extortion portal. Impacted individuals are being offered 12 months of free credit monitoring and identity protection.
UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data
Google and Mandiant attribute vishing-based SaaS data extortion attacks to UNC6671, now operating under the Redact, Pink, Helix, and Falcon brands.
Google Threat Intelligence Group and Mandiant track extortion group UNC6671, which uses vishing calls impersonating IT help desks to lure employees to adversary-in-the-middle phishing pages that capture credentials, MFA tokens, and session tokens. The group then registers adversary-controlled MFA devices, pivots through identity providers into Microsoft 365, Okta, and other SaaS applications, and runs automated Python and PowerShell exfiltration scripts. UNC6671 has rotated through extortion brands including BlackFile, Redact, Pink, Helix, and Falcon, and Google tracked over $10.6 million in Bitcoin payments between January 7 and May 12, 2026, with initial demands exceeding $3 million. The actor has hit dozens of organizations in North America, Australia, and the UK, shifting toward high-value financial and legal firms in July 2026.
ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories
Weekly ThreatsDay bulletin details a ShinyHunters-style social engineering hit on ReliaQuest, the 296,000-device Dysphoria IoT botnet, and several new malware families.
ReliaQuest confirmed a social engineering attack on August 22, 2026, in which an attacker used a fake SSO page and MFA push approval to gain brief view-only access to an identity dashboard, with tactics matching ShinyHunters, which has since listed the firm on its leak portal. The Shadowserver Foundation reported the Dysphoria botnet has compromised nearly 296,000 IoT devices for DDoS attacks and recently added residential proxy capability. Cisco Talos documented JWR, an operator-driven phishing-as-a-service framework linked to The Outsider that harvests credentials, identity documents, and 2FA codes over an encrypted WebSocket. New malware coverage includes the Octagon Android fraud bot ($1,400/month), the C2Looper Rust backdoor delivered via ClickFix, and the Aeternum loader that moved C2 to the Polygon blockchain.