ShinyHunters lists Baxter, Cook Medical, and Sharecare in one leak day

ShinyHunters listed Baxter, Cook Medical, and Sharecare on its leak site within a minute, claiming Salesforce records and corporate data from all three.

MedRisk Staff
By
2 Min Read

The ShinyHunters extortion gang listed three medical companies on its leak site within roughly a minute on August 14, in what trackers describe as a coordinated push against the healthcare sector.

Baxter International, the medical products giant, was told it faces publication of data unless it responds by August 17. The listing claims more than 7.1 million Salesforce records containing some personal information were taken. Cook Medical, an Indiana-based device maker, was listed with a claim of 182 GB of customer, employee, and internal corporate data. Sharecare, the digital health platform, was listed with claims of 3.4 million Salesforce records and more than 28 GB of corporate data, roughly 25 GB compressed.

All three postings are unconfirmed claims, and ShinyHunters has a record of exaggerating hauls. But the group has repeatedly targeted healthcare: it was linked to the DentaQuest incident that led to notifications for 15 million patients, and has claimed breaches at Medtronic and Amazon’s One Medical Seniors this year.

For hospital and health system security teams, the practical takeaway is vendor exposure. Salesforce instances and customer engagement platforms are common across care delivery organizations, and the claims suggest the gang is probing SaaS estates. Organizations should check whether any of their vendors touch Baxter, Cook, or Sharecare systems, and review Salesforce configuration for exposed portals and misconfigured sharing rules.

Share This Article