Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.
Reconnecting to live updates…

AdaptHealth confirms 4.1 million people exposed in July cyberattack

0
High
Breach
Published: 09/09/2026 (09/09/2026, 21:30:36 UTC)
Source: Bleeping Computer

Description

AdaptHealth, a healthcare company providing home medical devices and services, confirmed a data breach affecting 4.1 million individuals. The breach, discovered in July 2026 and attributed to the ShinyHunters threat group, involved unauthorized access to cloud-based business applications and internal patient management systems. The attackers gained access through a social engineering attack compromising a third-party contractor's privileged account. Exposed data includes personal and health information. AdaptHealth notified affected individuals and offered free credit monitoring. No evidence of identity theft or fraud has been found so far.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/09/2026, 21:37:19 UTC

Technical Analysis

In July 2026, AdaptHealth disclosed a cyberattack attributed to the ShinyHunters threat group that exposed data of approximately 4.1 million people. The breach originated from a social engineering attack that compromised a privileged account of a third-party contractor, allowing attackers to access cloud-based business applications, internal patient management systems, document storage, and electronic health record portals. The exposed data includes full names, contact and demographic information, health insurance details, and health information. AdaptHealth notified affected individuals and provided a 12-month free credit monitoring and identity protection service. The company has found no evidence of identity theft or misuse of the stolen data. The breach was first disclosed in an SEC filing on July 2, 2026, with the compromise occurring on June 5, 2026.

Potential Impact

The breach exposed sensitive personal and health-related information of over 4.1 million individuals, potentially risking privacy and confidentiality. Although no evidence of identity theft or fraud has been reported, the exposure of health insurance and health information could lead to future misuse or targeted attacks. The incident also highlights risks associated with third-party contractor access and social engineering attacks in healthcare environments.

Defensive Guidance

AdaptHealth has notified affected individuals and offered a free 12-month credit monitoring and identity protection service. The breach resulted from a social engineering attack compromising a third-party contractor's privileged account. Organizations should review and strengthen third-party access controls and implement enhanced monitoring for privileged accounts. Since this is a breach incident rather than a software vulnerability, no patch is applicable. Follow vendor and regulatory guidance for breach notification and remediation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.75,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/","fetched":true,"fetchedAt":"2026-09-09T21:37:13.942Z","wordCount":685}

Threat ID: 6aa1d189acd9273b49e5f000

Added to database: 09/09/2026, 21:37:13 UTC

Last enriched: 09/09/2026, 21:37:19 UTC

Last updated: 09/10/2026, 02:41:59 UTC

Views: 10

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses