CSIDB logo
Incident

AdaptHealth

Incident posture

Attack window
Jun 2026
Location
United States of America
Status
Unknown
CIA posture
Available to members
Updated
2026-09-10 07:31

Linked entities

Victim
AdaptHealth
Threat actors
1 actor
Sources
1 source

Timeline

Occurred
Jun 2026
Discovered
Jul 2026
Disclosed
Jul 2026
Resolved
Pending

Summary

AdaptHealth confirmed that a cyberattack exposed the data of approximately 4.1 million people after attackers compromised a privileged third-party contractor account through social engineering. The intrusion affected cloud-based business applications, including patient management systems, document storage platforms, and electronic health record portals, resulting in the exfiltration of names, contact and demographic details, health insurance information, and health information. The attack was attributed to ShinyHunters, which demanded ransom payment, and the company reported no evidence of identity theft, fraud, or other misuse.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

1 technique

Description

AdaptHealth, a healthcare company providing home medical devices, supplies, and related services, confirmed that a cyberattack exposed data belonging to approximately 4.1 million people. The intrusion was discovered in July 2026 and was attributed to the ShinyHunters threat group. AdaptHealth first disclosed the incident in a filing with the U.S. Securities and Exchange Commission on July 2, 2026, stating that attackers had accessed its systems and exfiltrated private data. Its investigation determined that the compromise had occurred earlier, beginning on June 5, and involved cloud-based business applications. The affected environment included certain internal patient management systems, document storage platforms, and portals associated with an electronic health record system. On June 15, an unnamed threat actor contacted AdaptHealth and demanded a ransom payment in exchange for not leaking the stolen data. The company later stated that the breach resulted from a successful social engineering ploy that compromised the privileged account of a third-party contractor.

In an August 14 update, AdaptHealth reported that the incident may have exposed full names, contact information, demographic information, health insurance information, and health information. A submission to the U.S. Department of Health and Human Services identified 4,115,802 affected individuals. The company’s website stated that AdaptHealth served about 4.1 million patients across all 50 U.S. states through 680 locations as of July 2024. Impacted individuals were expected to receive data breach notifications containing instructions for enrolling in a free 12-month credit monitoring and identity protection service. AdaptHealth stated that its investigation had found no evidence of identity theft, fraud, or other misuse of the stolen data. The HIPAA Journal had previously attributed the attack to ShinyHunters after the threat actor added AdaptHealth to its victim list. BleepingComputer reported that it could not locate an AdaptHealth entry on ShinyHunters’ extortion portal, indicating that the listing had been removed. AdaptHealth’s disclosure followed similar breach announcements from Aesto Health, CareCloud, and Unlimited Technology Systems, while McKesson and Nutex Health had also reported incidents without yet determining the number of affected individuals.

Sources

Sources available to members: 1 source.

CSIDB