Incident
Published 2026-09-09
Verified 2026-09-19

AdaptHealth: 4.1M people exposed after June contractor social-engineering breach

BleepingComputer (9 September 2026) reports AdaptHealth confirmed about 4.1 million people were exposed in a cyberattack discovered in July. SEC filing 2 July 2026 disclosed access to cloud business apps including patient management, document storage, and EHR portals. Company update: compromise on 5 June 2026 via social engineering of a third-party contractor's privileged account; ransomware demand around 15 June; data classes named include names, contact and demographic data, health insurance, and health information. HHS submission lists 4,115,802 individuals. Notifications and 12-month credit monitoring offered. Reporting attributes the actor to ShinyHunters; BleepingComputer could not find a current AdaptHealth listing on that group's portal. No Australian nexus identified this pass. Primary: BleepingComputer (company filings).

Exploited in Australia?
unknown

Primary: BleepingComputer — AdaptHealth 4.1M (9 Sep 2026)

breaches identity cloud