AdaptHealth confirms 4,115,802 people exposed in June 2026 cyberattack tied to third-party contractor compromise
AdaptHealth confirmed that 4,115,802 individuals were exposed in a cyberattack that began June 5, 2026, in which a socially engineered attacker used a third-party contractor account to steal names, contact details, demographic data, and health and insurance…
AdaptHealth has confirmed that 4,115,802 individuals were exposed in a cyberattack first disclosed in an SEC filing on July 2, 2026, with the compromise beginning June 5, 2026. Both outlets report the attacker used social engineering against a third-party contractor: BleepingComputer describes compromise of a privileged third-party contractor account, while SecurityWeek describes a hijacked user session at the contractor. Through that access, the intruder reached AdaptHealth cloud applications, including patient management, document storage and EHR portals, and exfiltrated names, contact details, demographic information, and health and health insurance data. SecurityWeek reports Social Security numbers and financial information were not affected. A ransom demand was made on June 15, 2026, apparently to prevent a data leak, and BleepingComputer attributes the attack to the ShinyHunters group, noting AdaptHealth no longer appears on the gang's extortion portal and no misuse of data has been observed so far. The figure of 4,115,802 affected individuals was reported to HHS, and the incident appeared on the HHS breach portal the week of the September 9-10, 2026 disclosures. Impacted individuals are being offered 12 months of free credit monitoring and identity protection. Separately, SecurityWeek notes Baylor Genetics reported 2,810,878 individuals affected in a related June healthcare breach.
- 4,115,802 individuals exposed, per AdaptHealth's breach submission to HHS; the incident was added to the HHS breach portal
- Initial access via social engineering against a third-party contractor (privileged account per BleepingComputer; hijacked user session per SecurityWeek)
- Compromise began June 5, 2026; first publicly disclosed in an SEC filing on July 2, 2026
- Data exfiltrated from cloud patient management, document storage and EHR systems: names, contact details, demographic information, and health and health insurance data
- Social Security numbers and financial information were not affected (per SecurityWeek)
- Ransom demand made on June 15, 2026 to prevent a data leak
- Attack attributed to ShinyHunters (per BleepingComputer); AdaptHealth no longer appears on the gang's extortion portal and no data misuse has been observed so far
- Affected individuals are being offered 12 months of free credit monitoring and identity protection
Coverage timelineoldest first · each row is one article
- · 6d agoAdaptHealth confirms 4.1 million people exposed in July cyberattack
BleepingComputer· 78
AdaptHealth confirmed a ShinyHunters-attributed cyberattack exposed data of 4.1 million patients via a compromised third-party contractor account.
- · 5d ago4.1 Million Impacted by AdaptHealth Data Breach
SecurityWeek· 76
AdaptHealth disclosed a breach affecting 4,115,802 people after a socially engineered attacker stole health and insurance data from cloud-based patient systems.