ShinyHunters has released approximately 7.1 million records allegedly stolen from Baxter International during an intrusion involving its third-party applications.
Baxter Cybersecurity Incident
Medical device manufacturer, Baxter International based in Deerfield, Illinois, reported unauthorized activity within certain third-party applications on August 13, 2026. Baxter activated its cybersecurity response procedures and began an investigation with assistance from third-party cybersecurity and digital forensics experts. The investigation remains ongoing to determine the types and amount of information that may have been accessed or acquired.
According to Baxter, the incident did not affect patient services, including its products, connected solutions, and technologies accessed by customers to deliver patient care. Business operations continued normally and the incident had no material impact on its finances.
The name of the threat group responsible for the incident had not been publicly disclosed when Baxter issued its statement.
ShinyHunters Claims Responsibility
On August 14, 2026, ShinyHunters added Baxter to its dark web data leak site and claimed responsibility for the attack. The group gave Baxter until August 17, 2026 to negotiate payment and threatened to leak the stolen data if no payment was made. On August 19, 2026, ShinyHunters released the stolen data for download.
ShinyHunters claims that 7.1 million Salesforce records were exfiltrated and that some of the records contained personally identifiable information (PII). There is no confirmation about the nature of the stolen data yet. Baxter only stated that the attack involved certain third-party apps and that its investigation is continuing.
The number of records claimed by ShinyHunters does not establish that 7.1 million patients were affected. Baxter stated that it will provide additional updates as information is confirmed.
ShinyHunters Healthcare Activity
The ShinyHunters threat group has targeted organizations across multiple sectors and that its list of victims includes HIPAA-covered healthcare organizations. In June 2026, ShinyHunters claimed to have stolen 8.8 terabytes of data from OneMedical, including the protected health information (PHI) of 153,000 patients. The group also claimed in June to have exfiltrated 234 GB of data from DentaQuest, including the PHI of approximately 2.6 million individuals.
In July 2026, Medtronic confirmed that PHI belonging to 3.8 million patients was stolen in an attack attributed to ShinyHunters. Other healthcare victims identified include Him & Hers, iRhythm, and AdaptHealth. Health-ISAC issued an alert to the healthcare and public health sector in July concerning the group.
Current Status of the Baxter Investigation
Baxter has not confirmed the nature or amount of information involved in the alleged data theft. Its investigation is continuing with assistance from third-party cybersecurity and digital forensics experts. The company has stated that it will provide updates as additional information is confirmed.
Image credit: 529839744 – piter2121, AdobeStock









