Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group.
The company provides home medical devices, supplies, and related services, including sleep-apnea and respiratory equipment, oxygen therapy, hospital beds, and mobility products.
AdaptHealth first disclosed the incident in a filing with the U.S. Securities and Exchange Commission (SEC) on July 2, 2026, informing that attackers accessed its systems and exfiltrated private data.
At the time, AdaptHealth’s investigation confirmed the intrusion occurred earlier and involved access to cloud-based business applications, including certain internal patient management systems, document storage platforms, and electronic health record system portals.
On June 15, an unnamed threat actor contacted AdaptHealth to demand a ransom payment in exchange for not leaking the stolen data.
AdaptHealth added that the breach occurred through a successful social engineering ploy that compromised the privileged account of a third-party contractor.
In an update on August 14, AdaptHealth informed that the compromise had occurred on June 5 and may have exposed the following data:
Full names
Contact information
Demographic information
... continue reading