ShinyHunters extortion wave hits Baxter, Alcon, Carhartt and more
ShinyHunters continues to demand payment from companies it says it breached through fake help-desk calls and stolen employee logins. McKesson says data was taken from third-party applications used by a subset of customers in its Oncology & Multispecialty and Medical-Surgical units. On August 31, McKesson said all business lines and distribution centers were operating and that it had reasonable assurance there was no ongoing unauthorized activity. ShinyHunters later claimed it breached Florida's DAVID driver database and stole more than 200,000 records. Florida has not confirmed that claim. ShinyHunters was still threatening to publish McKesson data on September 1, and no McKesson or Neogen leak had appeared in the latest credible reports. McKesson has not confirmed the group's claim of 284 million records.
- Started
- Aug 1, 2026
- Latest activity
- Sep 10, 2026
- Attributed to
- ShinyHuntersConfirmed
- Where
- United States, Switzerland, France
- Sectors
- Healthcare, Retail, Manufacturing, Technology, Multiple sectors
- Scale
- at least eleven organizations now named, including Baxter International, Alcon, Carhartt, Sharecare, Questel, Lumenis, Brinks Home
Current status
On September 10, Health-ISAC warned healthcare providers about ongoing ShinyHunters voice-phishing attacks, while GovInfoSecurity reported the Florida DAVID claim remained unconfirmed.
Active: Confirmed and still going. Attacker activity or disruption is continuing.
Who is behind it
ShinyHunters posted these claims, sample data, and negotiation transcripts itself on its own extortion leak site.
Impact
ShinyHunters claims to have taken customer, patient and employee data from Salesforce, Snowflake and other business systems across the affected companies. Stolen files from Carhartt, Sharecare and Baxter International have been published. Have I Been Pwned counted about 12.9 million Carhartt accounts, roughly half the group's original claim. For McKesson, the group claims 284 million rows of patient data, including names, addresses, phone numbers, birth dates, Social Security numbers and details about medical appointments and illnesses. Neither TechCrunch nor McKesson has verified the full dataset or the claimed count. ShinyHunters also claims to have stolen more than 200,000 Florida driver records, but that claim has not been confirmed by Florida. McKesson says its distribution centers, ordering and shipping remain operational. No McKesson or Neogen data has been confirmed published.
What to do
McKesson says customers do not need to act at this time. Watch for a notice from McKesson, Florida's highway safety agency or another named company before signing up for any support service. Treat unexpected calls or emails asking you to approve a login, reset a password or share a one-time code as possible phishing. Use contact details from the company's official website instead of links or phone numbers in an unexpected message. Carhartt customers can check Have I Been Pwned to see if their account appears in the confirmed leak.
Timeline
-
Sep 10, 2026
GovInfoSecurity reported that ShinyHunters still claimed to have stolen more than 200,000 Florida DAVID records. The claim remained unconfirmed by Florida. The group said it had lost access while officials worked to patch the alleged vulnerability.
Activegovinfosecurity.com -
Sep 10, 2026
Healthcare IT News reported that Health-ISAC warned healthcare providers about ShinyHunters voice-phishing attacks and lookalike domains used to steal access to cloud systems.
Activehealthcareitnews.com -
Sep 9, 2026
CSO Online reported that ShinyHunters set a September 11 deadline to publish the allegedly stolen Florida DAVID records. The claim remained unconfirmed by Florida.
Activecsoonline.com -
Sep 8, 2026
ShinyHunters claimed it breached Florida's DAVID driver database and stole more than 200,000 records, but Florida had not confirmed a breach.
Activebleepingcomputer.com -
Sep 2, 2026
McKesson's confirmation that hackers accessed third-party cloud applications and stole data tied to a subset of Oncology and Medical-Surgical customers was reported again by multiple outlets, restating the same facts from its August 31 statement with no new figures or scope.
Activefinance.yahoo.com -
Aug 31, 2026
The Register reported that Boston Scientific and McKesson each disclosed more details over the weekend about separate cyberattacks, noting Boston Scientific's incident disrupted pacemaker remote monitoring and shipping but has not been attributed to ShinyHunters or any named group.
Activetheregister.com -
Aug 31, 2026
ShinyHunters named food-safety and animal-health company Neogen as a new extortion target, setting a September 1 deadline. No stolen data samples had been published by the time of this check.
Activecybernews.com -
Aug 31, 2026
TechCrunch checked a small sample supplied by ShinyHunters against public records. McKesson said the stolen data relates to a subset of customers in its Oncology & Multispecialty and Medical-Surgical units, but it did not confirm the group's claimed record count.
Activetechcrunch.com -
Aug 31, 2026
McKesson told reporters that all business lines, distribution centers, ordering and shipping remained operational, and that it had reasonable assurance there was no ongoing unauthorized activity in its systems. Its investigation remains open, while ShinyHunters was still threatening to publish the stolen data on September 1.
Activegovinfosecurity.com -
Aug 29, 2026
Cybernews reported that ShinyHunters is claiming it stole about 284 million patient data records from McKesson through third-party application access; McKesson has not confirmed this figure.
Activecybernews.com -
Aug 28, 2026
ShinyHunters said it demanded $55,236,150 from McKesson with a 72 hour deadline after finishing the data theft on August 25, and that McKesson did not respond to or negotiate the ransom demand.
Activebleepingcomputer.com -
Aug 28, 2026
ShinyHunters told BleepingComputer it broke into McKesson using phone-based social engineering (vishing) against multiple employees, compromising their Okta single sign-on accounts and then accessing McKesson's Salesforce and Snowflake environments to pull about 1TB of data between August 21 and 25.
Activebleepingcomputer.com -
Aug 28, 2026
McKesson disclosed a cybersecurity incident in an SEC Form 8-K filing after ShinyHunters claimed responsibility, saying it discovered the incident on August 25, 2026 and that its investigation is still in an early stage; McKesson has not called the incident material and warned customers of possible intermittent service issues.
Activesec.gov -
Aug 27, 2026
Have I Been Pwned added the Carhartt breach to its database, listing about 12.9 million affected accounts, corroborating The Register's independent count from a day earlier.
Activebleepingcomputer.com -
Aug 26, 2026
An independent review by The Register of the published Carhartt files found the breach actually affected about 12.9 million records, roughly half of the number ShinyHunters had originally claimed.
Activetheregister.com -
Aug 25, 2026
ShinyHunters named CyrusOne, a data center operator whose facilities serve Microsoft and Meta, as a new victim, claiming it took Salesforce records, employee data, contracts and security files, and demanding 13 million dollars with about a four day deadline. CyrusOne has not confirmed a breach.
Activecybernews.com -
Aug 25, 2026
ReliaQuest formally confirmed no data was accessed in the ShinyHunters-linked social engineering attempt, saying one employee's identity session was briefly compromised but the attacker got no further.
Activecyberdaily.au -
Aug 24, 2026
Health-ISAC issued a TLP WHITE advisory describing the ReliaQuest incident as a voice-phishing and lookalike-SSO campaign on August 22 that briefly gave the attacker an authenticated identity session before device-trust controls blocked further movement, with zero unauthorized access to internal applications, customer environments, or telemetry.
Activeaha.org -
Aug 24, 2026
ReliaQuest disputed the scope of the claimed breach, saying the attacker's social engineering attempt only reached one employee's identity dashboard and got no further into its systems.
Activetheregister.com -
Aug 23, 2026
ShinyHunters listed US cybersecurity firm ReliaQuest on its leak site and posted screenshots of an internal Okta dashboard, claiming a new breach.
Activecybernews.com -
Aug 21, 2026
ShinyHunters published Baxter International's stolen data on its darkweb leak site, claiming 7.1 million Salesforce records including personal data, after saying Baxter would not agree to its demands.
Activegovinfosecurity.com -
Aug 20, 2026
Cyber Daily reported that ShinyHunters' ultimatum against Logitech's Streamlabs unit still stands, with the group threatening further disruption if the August 21 deadline passes without payment.
Activecyberdaily.au -
Aug 18, 2026
ShinyHunters claimed Logitech's Streamlabs unit as a new victim, threatening to leak data unless paid by August 21, showing the broader campaign is still active.
Activecybernews.com -
Aug 14, 2026
ShinyHunters posted a new claim against Baxter International, giving a leak deadline of August 17.
Activeransomware.live -
Aug 13, 2026
ShinyHunters published stolen Sharecare and Carhartt data after saying both companies' negotiators walked away from talks.
Activeransomware.live -
Aug 8, 2026
ShinyHunters claimed a large unnamed company, saying it took 11.5 million records across Salesforce, ServiceNow and Entra.
Activeransomware.live -
Aug 3, 2026
Brinks Home confirmed unauthorized access to its systems after ShinyHunters leaked 41GB of data, saying alarm monitoring was not affected.
Activesecurityweek.com -
Aug 1, 2026
ShinyHunters posted extortion claims against Questel, Lumenis and Alcon, saying it took Salesforce records and internal files from each.
Activeransomware.live
Sources
- Shinyhunters ransomware claims Baxter International, Inc. ransomware.live Aug 14, 2026
- Shinyhunters ransomware claims Carhartt, Inc. ransomware.live Aug 13, 2026
- Shinyhunters ransomware claims Sharecare, Inc. ransomware.live Aug 13, 2026
- Shinyhunters ransomware claims Questel SAS ransomware.live Aug 1, 2026
- Shinyhunters ransomware claims Alcon Inc. ransomware.live Aug 1, 2026
- Brinks Home breach: ShinyHunters leaks 41GB of data SecurityWeek Aug 3, 2026
- Logitech subsidiary, beloved by Twitch streamers, allegedly breached cybernews.com Aug 18, 2026
- Pay or leak: ShinyHunters delivers ultimatum to Logitech Cyber Daily Aug 20, 2026
- ShinyHunters Leaks 7.1 Million Baxter International Records GovInfoSecurity Aug 21, 2026
- ShinyHunters Leaks 7.1 Million Baxter International Records BankInfoSecurity Aug 21, 2026
- ShinyHunters and ReliaQuest trade blows over claimed breach The Register Aug 24, 2026
- ReliaQuest allegedly breached as ShinyHunters posts Okta dashboard Cybernews Aug 24, 2026
- ReliaQuest says no data accessed after failed ShinyHunters social engineering attempt Cyber Daily Aug 25, 2026
- ReliaQuest confirms failed data-theft attack after ShinyHunters breach Bleeping Computer Aug 24, 2026
- ReliaQuest Confirms ShinyHunters Hack, but Says Impact Was Limited SecurityWeek Aug 24, 2026
- ReliaQuest Rejects Compromise Claims After ShinyHunters Incident Infosecurity Magazine Aug 25, 2026
- ShinyHunters strikes at security firm ReliaQuest Techzine Europe Aug 25, 2026
- H-ISAC TLP WHITE Cyber Incidents: ShinyHunters-Linked Social Engineering and Identity-Targeting Campaign American Hospital Association (H-ISAC) Aug 24, 2026
- Microsoft's and Meta's data center may have been breached in $13 million extortion attempt Cybernews Aug 25, 2026
- ShinyHunters hackers claim to have hit data center provider used by Microsoft and Meta TechRadar Aug 26, 2026
- Carhartt data breach affects 12.9M, half of what ShinyHunters claimed The Register Aug 26, 2026
- Carhartt data breach exposes information of 12.9 million accounts Bleeping Computer Aug 27, 2026
- McKesson discloses breach after ShinyHunters claims patient data theft BleepingComputer Aug 28, 2026
- McKesson data breach exposing 284 million patients CyberInsider Aug 28, 2026
Related reports
- Shinyhunters ransomware claims Logitech/ Streamlabs Aug 18, 2026
- Shinyhunters ransomware claims Baxter International, Inc. Aug 14, 2026
- Shinyhunters ransomware claims Sharecare, Inc. Aug 13, 2026
- Shinyhunters ransomware claims Carhartt, Inc. Aug 13, 2026
- ShinyHunters claims data theft from redacted organization Aug 8, 2026
- Shinyhunters ransomware claims Questel SAS Aug 1, 2026
- ShinyHunters claims data theft from Lumenis Aug 1, 2026
- Shinyhunters ransomware claims Alcon Inc. Aug 1, 2026
- Shinyhunters ransomware claims RingCentral, Inc. Jul 27, 2026
- ShinyHunters claims attack on Ernst & Young Jul 27, 2026
- EY breach threatens to expose client tax data Jul 27, 2026