Baxter International
Incident posture
Linked entities
- Victim
- Baxter International
- Threat actors
- 1 actor
- Sources
- 1 source
Timeline
Summary
The ShinyHunters data extortion group claimed responsibility for an intrusion at the medical device manufacturer, leaking approximately 7.1 million records allegedly stolen during the attack after the company reportedly refused to negotiate payment. The incident was detected when unauthorized activity was identified within certain third-party applications, prompting the activation of cybersecurity response procedures and an ongoing investigation with external digital forensics support. ShinyHunters claims the exfiltrated data consisted of Salesforce records containing personally identifiable information, though the organization has not publicly confirmed the nature of the stolen data or whether all 7.1 million records pertain to patients. The company stated that patient services, business continuity, products, and connected technologies used for patient care were unaffected, and no material financial impact is anticipated.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
On August 13, 2026, Baxter International, a Deerfield, Illinois-based medical device manufacturer, detected unauthorized activity within certain third-party applications used by the company. Upon detecting the intrusion, Baxter immediately activated its cybersecurity response procedures and launched an investigation, engaging third-party cybersecurity and digital forensics experts to assist with the inquiry. The company stated publicly that the incident did not have any impact on patient services or business continuity, noting that Baxter continued to operate normally. Baxter also indicated that the incident had not affected its products, connected solutions, or technologies used by customers to deliver patient care. The organization further noted that it did not anticipate the incident having a material impact on its financials or results of operations. At that time, Baxter did not publicly disclose the identity of any threat group behind the incident and did not specify the types or volume of information potentially accessed or acquired.
On August 14, 2026, the ShinyHunters data theft and extortion group added Baxter International to its dark web data leak site, publicly claiming responsibility for the attack. ShinyHunters issued an August 17, 2026, deadline for Baxter to negotiate payment, threatening to release the stolen data if the extortion demand was not met. When negotiations either did not occur or broke down—Baxter has not publicly commented on the status of any negotiations—the threat actor proceeded with its threat. On August 19, 2026, ShinyHunters released the stolen data for download on its leak site. The data leak site subsequently listed approximately 7.1 million records allegedly exfiltrated from Baxter's environment during the intrusion. ShinyHunters claimed that the stolen records consisted of Salesforce data, some of which contained personally identifiable information. Baxter was added to the leak site one day after the company issued its initial public statement about the cybersecurity incident, suggesting a deliberate escalation by the threat actor timed to the company's disclosure.
Baxter has not publicly confirmed the exact nature, type, or scope of the data stolen in the incident, only stating that the attack involved certain third-party applications. The company indicated that the investigation remained ongoing as of late August 2026 to determine the types and amount of information that may have been accessed or acquired during the unauthorized activity. While ShinyHunters claimed possession of 7.1 million records, this figure does not necessarily equate to 7.1 million affected patients, as the records could include duplicate entries, business contact information, or other non-patient data. Baxter stated that it would provide updates as additional information was confirmed through the ongoing investigation and digital forensics review.
The incident fits a broader pattern of ShinyHunters activity targeting large organizations, with a notable concentration of attacks against healthcare entities throughout 2026. In June 2026, ShinyHunters claimed to have exfiltrated 8.8 terabytes of data from Amazon-owned OneMedical, including the protected health information of 153,000 patients. Also in June, the group claimed responsibility for exfiltrating 234 GB of data from DentaQuest, which allegedly included the protected health information of approximately 2.6 million individuals. In July 2026, Medtronic, another medical device manufacturer, confirmed that the protected health information of 3.8 million patients was stolen in an attack attributed to ShinyHunters. Additional healthcare victims claimed by the group during this period include iRhythm, AdaptHealth, and Him & Hers. The pattern of healthcare targeting prompted Health-ISAC to issue an alert in July 2026 to the healthcare and public health sector specifically warning about ShinyHunters activity.
In Baxter's case, the company has not provided a definitive timeline for when the unauthorized actor first gained access to its third-party applications, nor has it disclosed when the data exfiltration occurred relative to the August 13 detection date. The investigation involving third-party cybersecurity and digital forensics experts is expected to clarify these details, along with the precise categories of records involved. Baxter's public statements have consistently emphasized that core operations, product availability, and patient care delivery systems were not disrupted by the incident, distinguishing the data theft event from operational outages that have affected other ransomware and extortion victims. The company's response has been limited to confirming the detection, activating response procedures, engaging external forensic support, and committing to provide further updates once the scope of compromised data is validated.
Sources
Sources available to members: 1 source.