ShinyHunters has released roughly 7.1 million records it says were stolen from Baxter International, the Deerfield, Illinois maker of renal care systems, infusion pumps, and surgical products. The dump went public on August 19 after Baxter declined to meet the group’s ransom deadline, according to the HIPAA Journal.
Baxter disclosed the intrusion in an August 13 statement, saying unauthorized access involved certain third-party applications. The company said patient services, products, and connected technologies were unaffected and that operations continue normally.
The group claims the stolen data consists of 7.1 million Salesforce records, some containing personally identifiable information. Baxter has not confirmed the contents or the volume of the leaked files. The listing followed the pattern ShinyHunters has used against other healthcare targets, including a June 2026 claim of 8.8 terabytes of Amazon-owned One Medical data.
The incident extends a string of ShinyHunters healthcare victims that prompted Health-ISAC to warn member organizations about the group’s tactics. The operation, one of the most active data-theft crews, has claimed everything from health systems to device makers over the past year.
For hospitals and clinics that share Salesforce environments with Baxter or other vendors, the exposure raises phishing and credential-theft risks, since dumped email addresses and PII can fuel targeted social engineering. Security teams should watch for suspicious messages referencing Baxter or third-party applications, review vendor-connected Salesforce instances, and remind staff to verify unexpected login prompts.