TTO-2026-0910-113 · September 10, 2026 Data BreachHealthcare

AdaptHealth Confirms 4.1 Million People Exposed in ShinyHunters Attack via Third-Party Contractor Session

adapthealth.comShinyHunters4,115,802 affectedHealth and insurance dataThird-party contractor social engineeringHHS confirmed

Summary

AdaptHealth, a home medical equipment company operating over 680 facilities across the United States, has confirmed that a cyberattack first disclosed in July 2026 exposed the personal, health, and insurance information of 4,115,802 individuals. The attack was attributed to the ShinyHunters threat group and gained entry through social engineering of a third-party contractor's user session, giving the attacker access to AdaptHealth's cloud-based patient management systems, document storage, and electronic health record portals. The breach was formally reported to the U.S. Department of Health and Human Services, which added the incident to its public data breach portal this week. Social Security numbers and financial information were not affected.

Timeline

DateEvent
June 5, 2026Attacker compromises a third-party contractor's privileged account via social engineering and accesses AdaptHealth's cloud environment
June 27, 2026AdaptHealth files disclosure with the SEC; confirms theft of patient records and insurance billing passwords
July 4, 2026AdaptHealth publicly discloses the cyberattack
Aug 14, 2026AdaptHealth notifies HHS, reporting 4,115,802 affected individuals; offers 12-month free credit monitoring
Sep 10, 2026HHS adds AdaptHealth to its public data breach portal; breach confirmed at scale

What Happened

The attacker used social engineering to trick a third-party contractor into surrendering login credentials, then used those credentials to enter AdaptHealth's cloud-based infrastructure. From there, the attacker accessed internal patient management systems and document storage platforms, exfiltrating names, contact and demographic information, health information, and health insurance details, as well as a password file associated with insurance billing. No Social Security numbers or financial account data were confirmed stolen.

AdaptHealth has notified all 4,115,802 affected individuals and enrolled them in a 12-month credit monitoring and identity protection service. The company reports no evidence the stolen data has been used for identity theft or fraud as of this publication. The incident follows a pattern consistent with other ShinyHunters campaigns that use contractor access as an entry point — a supply-chain access pattern also seen in the ShinyHunters Florida DAVID breach documented in TTO-2026-0908-111.

Domain Intelligence

adapthealth.com — 60.15

Score sits in the low-trust range. AdaptHealth is the breached organization. The score reflects adapthealth.com's domain trust posture as assessed prior to and independently of this incident.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 10, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 8, 2026
Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · September 7, 2026