LIVE · cybersecurity feed
Live wire
Acronis warns of actively exploited flaw in its cPanel backup pluginOracle September 2026 Critical Security Patch Update addresses 672 CVEsCVE-2026-76461 · U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogHackers target WordPress sites via third-party WooCommerce pluginCVE-2026-51990 · Hackers exploit Tencent app flaw to deploy GrayRabbit malwareCVE-2026-42016 · CISA Adds 5 Exploited Flaws in Artifactory, ScreenConnect, RouterOS to KEVCVE-2026-85102 · Dutch NCSC: Critical Check Point VPN flaws exploitation is imminentAI Enables Mass Generation of Personalized Fraud EmailsCVE-2026-85706 · Critical GitLab Vulnerability Exploited in Internet-Wide ProbesCVE-2025-66516 · Metasploit Wrap Up: This One Goes to Sixteen!
breach

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. [...]

zeroday.news ·

AdaptHealth, a provider of home medical devices and services, has confirmed that a cyberattack discovered in July exposed the data of 4.1 million individuals. The company offers a range of equipment and services, including those for sleep apnea, respiratory care, oxygen therapy, hospital beds, and mobility.

The incident was initially disclosed by AdaptHealth in a U.S. Securities and Exchange Commission (SEC) filing on July 2, 2026. At that time, the company reported that attackers had accessed its systems and exfiltrated private data. The investigation confirmed that the intrusion occurred earlier and involved access to cloud-based business applications, including internal patient management systems, document storage platforms, and electronic health record system portals.

On June 15, an unidentified threat actor contacted AdaptHealth, demanding a ransom payment to prevent the leakage of the stolen data. AdaptHealth stated that the breach was a result of a successful social engineering tactic that compromised a privileged account belonging to a third-party contractor.

An update on August 14 specified that the compromise took place on June 5. The exposed data potentially includes full names, contact information, demographic details, health insurance information, and general health information.

AdaptHealth has begun sending data breach notifications to affected individuals, which include instructions for enrolling in a complimentary 12-month credit monitoring and identity protection service. The company has stated that as of its last update, there was no evidence of identity theft, fraud, or other misuse of the stolen data.

According to information on AdaptHealth's website, as of July 2024, the company served approximately 4.1 million patients across all 50 U.S. states through a network of 680 locations. A submission to the U.S. Department of Health and Human Services indicates that the breach specifically affects 4,115,802 individuals.

While the ShinyHunters threat group was previously linked to the attack based on claims of adding AdaptHealth to their list of victims, the company's entry could not be found on ShinyHunters' extortion portal, suggesting it may have been removed.

This disclosure from AdaptHealth follows similar recent reports from other health-tech firms. Aesto Health, CareCloud, and Unlimited Technology Systems have also confirmed data breaches. Additionally, McKesson and Nutex Health disclosed incidents late last month, though they have not yet determined the number of impacted individuals.

breachnation-statehealthcare
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

CVE-2026-76461critical

U.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Cisco Secure Email Gateway flaw, tracked as CVE-2026-76461 (CVSS score of 9,8), to its Known Exploited Vulnerabilities (KEV) catalog. Cisco disclosed a critical zero-day CVE-2026-76

patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]

ai

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.