ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

AdaptHealth confirms 4,115,802 people exposed in June 2026 cyberattack tied to third-party contractor compromise

highData breachimportance 78
What's new: First merged summary for this story (no prior version). New developments as of September 9-10, 2026: the confirmed count of 4,115,802 exposed individuals was filed with HHS and listed on the HHS breach portal, prompting the public disclosures. Newly reported details include the June 5 start of the compromise, the June 15 ransom demand, ShinyHunters attribution, confirmation that Social Security…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

AdaptHealth confirmed that 4,115,802 individuals were exposed in a cyberattack that began June 5, 2026, in which a socially engineered attacker used a third-party contractor account to steal names, contact details, demographic data, and health and insurance…

AdaptHealth has confirmed that 4,115,802 individuals were exposed in a cyberattack first disclosed in an SEC filing on July 2, 2026, with the compromise beginning June 5, 2026. Both outlets report the attacker used social engineering against a third-party contractor: BleepingComputer describes compromise of a privileged third-party contractor account, while SecurityWeek describes a hijacked user session at the contractor. Through that access, the intruder reached AdaptHealth cloud applications, including patient management, document storage and EHR portals, and exfiltrated names, contact details, demographic information, and health and health insurance data. SecurityWeek reports Social Security numbers and financial information were not affected. A ransom demand was made on June 15, 2026, apparently to prevent a data leak, and BleepingComputer attributes the attack to the ShinyHunters group, noting AdaptHealth no longer appears on the gang's extortion portal and no misuse of data has been observed so far. The figure of 4,115,802 affected individuals was reported to HHS, and the incident appeared on the HHS breach portal the week of the September 9-10, 2026 disclosures. Impacted individuals are being offered 12 months of free credit monitoring and identity protection. Separately, SecurityWeek notes Baylor Genetics reported 2,810,878 individuals affected in a related June healthcare breach.

  • 4,115,802 individuals exposed, per AdaptHealth's breach submission to HHS; the incident was added to the HHS breach portal
  • Initial access via social engineering against a third-party contractor (privileged account per BleepingComputer; hijacked user session per SecurityWeek)
  • Compromise began June 5, 2026; first publicly disclosed in an SEC filing on July 2, 2026
  • Data exfiltrated from cloud patient management, document storage and EHR systems: names, contact details, demographic information, and health and health insurance data
  • Social Security numbers and financial information were not affected (per SecurityWeek)
  • Ransom demand made on June 15, 2026 to prevent a data leak
  • Attack attributed to ShinyHunters (per BleepingComputer); AdaptHealth no longer appears on the gang's extortion portal and no data misuse has been observed so far
  • Affected individuals are being offered 12 months of free credit monitoring and identity protection

Coverage timeline

  1. · 6d ago
    BleepingComputer· 78
    AdaptHealth confirms 4.1 million people exposed in July cyberattack

    AdaptHealth confirmed a ShinyHunters-attributed cyberattack exposed data of 4.1 million patients via a compromised third-party contractor account.

  2. · 5d ago
    SecurityWeek· 76
    4.1 Million Impacted by AdaptHealth Data Breach

    AdaptHealth disclosed a breach affecting 4,115,802 people after a socially engineered attacker stole health and insurance data from cloud-based patient systems.