ShinyHunters, a notorious extortion group, has made headlines once again by targeting the healthcare industry. The group claims to have leaked a staggering 7.1 million Salesforce records from Baxter International, a prominent medical device manufacturer. This breach allegedly includes sensitive personally identifiable information.

The Extortion Threat
In a recent post on their dark web forum, ShinyHunters expressed frustration at Baxter’s refusal to negotiate, stating, “The company failed to reach an agreement with us despite our incredible patience, all the chances and offers we made. They don’t care.” The post included a link for downloading the purportedly stolen data, further escalating the threat.
Baxter International’s Response
Baxter, headquartered in Deerfield, Illinois, confirmed on August 13 that it had detected “unauthorized activity” related to third-party applications. However, the company did not explicitly acknowledge ShinyHunters or the specific claims about the Salesforce records.
Baxter reassured stakeholders that the breach had not adversely affected manufacturing operations, customer services, or patient care. The company stated, “We have no evidence that this activity affected Baxter products, connected solutions, or technologies used by customers to deliver patient care.”
Ongoing Investigations
In response to the breach, Baxter activated its cybersecurity protocols and enlisted independent cybersecurity and forensic experts to assess the situation. The company is currently evaluating the extent of the information accessed or acquired, with an ongoing investigation to ascertain the full impact.
Despite these alarming developments, Baxter, which reported global net sales of $11.24 billion in 2025, does not anticipate any significant financial or operational repercussions from this cyber incident at this time.
A Pattern of Targeting Healthcare
Baxter is not alone in falling victim to ShinyHunters. The group has previously targeted various organizations within the healthcare sector, including DentaQuest, a major U.S. administrator of dental and vision benefits. In June, ShinyHunters claimed to have published 234 gigabytes of DentaQuest data, affecting 2.6 million individuals.
DentaQuest later disclosed that the breach affected 15 million people, marking it as one of the largest health data breaches recorded in 2026. The compromised information included sensitive details such as names, addresses, Social Security numbers, and health information.
Other Notable Breaches
Another recent victim of ShinyHunters is One Medical Group, an Amazon subsidiary that provides primary care services. In June, the group claimed to have stolen and leaked 8.8 terabytes of data from One Medical. The breach has affected over 153,000 individuals, according to a notice issued by One Medical after reporting the incident to the Department of Health and Human Services.
One Medical clarified that the breach involved unauthorized access to a third-party file-storage system and primarily impacted legacy patients from its acquisition of Iora Health in 2021.
Cross-Industry Impacts
The reach of ShinyHunters extends beyond healthcare, impacting various sectors, including education, retail, and manufacturing. The group has exploited vulnerabilities in different systems, including a zero-day vulnerability in Oracle PeopleSoft, affecting over 100 organizations globally, including universities.
Conclusion
The recent breach affecting Baxter International highlights the growing threats posed by cybercriminals in the healthcare sector. As organizations grapple with the complexities of cybersecurity, the need for robust defense mechanisms becomes increasingly critical. Stakeholders must remain vigilant and proactive in safeguarding sensitive information against such evolving threats.
- Key Takeaways:
- ShinyHunters claims to have leaked 7.1 million records from Baxter International.
- Baxter reported no immediate operational impact but is conducting an ongoing investigation.
- The group has targeted multiple healthcare organizations, indicating a troubling trend in cybercrime.
- Organizations across various industries must prioritize cybersecurity to protect sensitive data.
Read more β www.govinfosecurity.com
