Active High impact Data breach Checked 1d ago

ShinyHunters extortion wave hits Baxter, Alcon, Carhartt and more

ShinyHunters continues to demand payment from companies it says it breached through fake help-desk calls and stolen employee logins. McKesson says data was taken from third-party applications used by a subset of customers in its Oncology & Multispecialty and Medical-Surgical units. On August 31, McKesson said all business lines and distribution centers were operating and that it had reasonable assurance there was no ongoing unauthorized activity. ShinyHunters later claimed it breached Florida's DAVID driver database and stole more than 200,000 records. Florida has not confirmed that claim. ShinyHunters was still threatening to publish McKesson data on September 1, and no McKesson or Neogen leak had appeared in the latest credible reports. McKesson has not confirmed the group's claim of 284 million records.

Started
Aug 1, 2026
Latest activity
Sep 10, 2026
Attributed to
ShinyHuntersConfirmed
Where
United States, Switzerland, France
Sectors
Healthcare, Retail, Manufacturing, Technology, Multiple sectors
Scale
at least eleven organizations now named, including Baxter International, Alcon, Carhartt, Sharecare, Questel, Lumenis, Brinks Home

Current status

On September 10, Health-ISAC warned healthcare providers about ongoing ShinyHunters voice-phishing attacks, while GovInfoSecurity reported the Florida DAVID claim remained unconfirmed.

Active: Confirmed and still going. Attacker activity or disruption is continuing.

Who is behind it

ShinyHunters posted these claims, sample data, and negotiation transcripts itself on its own extortion leak site.

Impact

ShinyHunters claims to have taken customer, patient and employee data from Salesforce, Snowflake and other business systems across the affected companies. Stolen files from Carhartt, Sharecare and Baxter International have been published. Have I Been Pwned counted about 12.9 million Carhartt accounts, roughly half the group's original claim. For McKesson, the group claims 284 million rows of patient data, including names, addresses, phone numbers, birth dates, Social Security numbers and details about medical appointments and illnesses. Neither TechCrunch nor McKesson has verified the full dataset or the claimed count. ShinyHunters also claims to have stolen more than 200,000 Florida driver records, but that claim has not been confirmed by Florida. McKesson says its distribution centers, ordering and shipping remain operational. No McKesson or Neogen data has been confirmed published.

What to do

McKesson says customers do not need to act at this time. Watch for a notice from McKesson, Florida's highway safety agency or another named company before signing up for any support service. Treat unexpected calls or emails asking you to approve a login, reset a password or share a one-time code as possible phishing. Use contact details from the company's official website instead of links or phone numbers in an unexpected message. Carhartt customers can check Have I Been Pwned to see if their account appears in the confirmed leak.

Timeline

  1. Sep 10, 2026

    GovInfoSecurity reported that ShinyHunters still claimed to have stolen more than 200,000 Florida DAVID records. The claim remained unconfirmed by Florida. The group said it had lost access while officials worked to patch the alleged vulnerability.

    Activegovinfosecurity.com
  2. Sep 10, 2026

    Healthcare IT News reported that Health-ISAC warned healthcare providers about ShinyHunters voice-phishing attacks and lookalike domains used to steal access to cloud systems.

    Activehealthcareitnews.com
  3. Sep 9, 2026

    CSO Online reported that ShinyHunters set a September 11 deadline to publish the allegedly stolen Florida DAVID records. The claim remained unconfirmed by Florida.

    Activecsoonline.com
  4. Sep 8, 2026

    ShinyHunters claimed it breached Florida's DAVID driver database and stole more than 200,000 records, but Florida had not confirmed a breach.

    Activebleepingcomputer.com
  5. Sep 2, 2026

    McKesson's confirmation that hackers accessed third-party cloud applications and stole data tied to a subset of Oncology and Medical-Surgical customers was reported again by multiple outlets, restating the same facts from its August 31 statement with no new figures or scope.

    Activefinance.yahoo.com
  6. Aug 31, 2026

    The Register reported that Boston Scientific and McKesson each disclosed more details over the weekend about separate cyberattacks, noting Boston Scientific's incident disrupted pacemaker remote monitoring and shipping but has not been attributed to ShinyHunters or any named group.

    Activetheregister.com
  7. Aug 31, 2026

    ShinyHunters named food-safety and animal-health company Neogen as a new extortion target, setting a September 1 deadline. No stolen data samples had been published by the time of this check.

    Activecybernews.com
  8. Aug 31, 2026

    TechCrunch checked a small sample supplied by ShinyHunters against public records. McKesson said the stolen data relates to a subset of customers in its Oncology & Multispecialty and Medical-Surgical units, but it did not confirm the group's claimed record count.

    Activetechcrunch.com
  9. Aug 31, 2026

    McKesson told reporters that all business lines, distribution centers, ordering and shipping remained operational, and that it had reasonable assurance there was no ongoing unauthorized activity in its systems. Its investigation remains open, while ShinyHunters was still threatening to publish the stolen data on September 1.

    Activegovinfosecurity.com
  10. Aug 29, 2026

    Cybernews reported that ShinyHunters is claiming it stole about 284 million patient data records from McKesson through third-party application access; McKesson has not confirmed this figure.

    Activecybernews.com
  11. Aug 28, 2026

    ShinyHunters said it demanded $55,236,150 from McKesson with a 72 hour deadline after finishing the data theft on August 25, and that McKesson did not respond to or negotiate the ransom demand.

    Activebleepingcomputer.com
  12. Aug 28, 2026

    ShinyHunters told BleepingComputer it broke into McKesson using phone-based social engineering (vishing) against multiple employees, compromising their Okta single sign-on accounts and then accessing McKesson's Salesforce and Snowflake environments to pull about 1TB of data between August 21 and 25.

    Activebleepingcomputer.com
  13. Aug 28, 2026

    McKesson disclosed a cybersecurity incident in an SEC Form 8-K filing after ShinyHunters claimed responsibility, saying it discovered the incident on August 25, 2026 and that its investigation is still in an early stage; McKesson has not called the incident material and warned customers of possible intermittent service issues.

    Activesec.gov
  14. Aug 27, 2026

    Have I Been Pwned added the Carhartt breach to its database, listing about 12.9 million affected accounts, corroborating The Register's independent count from a day earlier.

    Activebleepingcomputer.com
  15. Aug 26, 2026

    An independent review by The Register of the published Carhartt files found the breach actually affected about 12.9 million records, roughly half of the number ShinyHunters had originally claimed.

    Activetheregister.com
  16. Aug 25, 2026

    ShinyHunters named CyrusOne, a data center operator whose facilities serve Microsoft and Meta, as a new victim, claiming it took Salesforce records, employee data, contracts and security files, and demanding 13 million dollars with about a four day deadline. CyrusOne has not confirmed a breach.

    Activecybernews.com
  17. Aug 25, 2026

    ReliaQuest formally confirmed no data was accessed in the ShinyHunters-linked social engineering attempt, saying one employee's identity session was briefly compromised but the attacker got no further.

    Activecyberdaily.au
  18. Aug 24, 2026

    Health-ISAC issued a TLP WHITE advisory describing the ReliaQuest incident as a voice-phishing and lookalike-SSO campaign on August 22 that briefly gave the attacker an authenticated identity session before device-trust controls blocked further movement, with zero unauthorized access to internal applications, customer environments, or telemetry.

    Activeaha.org
  19. Aug 24, 2026

    ReliaQuest disputed the scope of the claimed breach, saying the attacker's social engineering attempt only reached one employee's identity dashboard and got no further into its systems.

    Activetheregister.com
  20. Aug 23, 2026

    ShinyHunters listed US cybersecurity firm ReliaQuest on its leak site and posted screenshots of an internal Okta dashboard, claiming a new breach.

    Activecybernews.com
  21. Aug 21, 2026

    ShinyHunters published Baxter International's stolen data on its darkweb leak site, claiming 7.1 million Salesforce records including personal data, after saying Baxter would not agree to its demands.

    Activegovinfosecurity.com
  22. Aug 20, 2026

    Cyber Daily reported that ShinyHunters' ultimatum against Logitech's Streamlabs unit still stands, with the group threatening further disruption if the August 21 deadline passes without payment.

    Activecyberdaily.au
  23. Aug 18, 2026

    ShinyHunters claimed Logitech's Streamlabs unit as a new victim, threatening to leak data unless paid by August 21, showing the broader campaign is still active.

    Activecybernews.com
  24. Aug 14, 2026

    ShinyHunters posted a new claim against Baxter International, giving a leak deadline of August 17.

    Activeransomware.live
  25. Aug 13, 2026

    ShinyHunters published stolen Sharecare and Carhartt data after saying both companies' negotiators walked away from talks.

    Activeransomware.live
  26. Aug 8, 2026

    ShinyHunters claimed a large unnamed company, saying it took 11.5 million records across Salesforce, ServiceNow and Entra.

    Activeransomware.live
  27. Aug 3, 2026

    Brinks Home confirmed unauthorized access to its systems after ShinyHunters leaked 41GB of data, saying alarm monitoring was not affected.

    Activesecurityweek.com
  28. Aug 1, 2026

    ShinyHunters posted extortion claims against Questel, Lumenis and Alcon, saying it took Salesforce records and internal files from each.

    Activeransomware.live

Sources

Related reports