Healthcare data just had a brutal day. McKesson confirmed ShinyHunters stole more than 284 million patient records and demanded $55 million, Baylor Genetics disclosed a breach touching 2.8 million people, Aesto Health said 9.5 million patients were exposed through an AWS compromise, and Novocure and Nutex Health both reported cancer and hospital patient data stolen. Boston Scientific is still cleaning up an intrusion serious enough to delay activation of implanted heart devices.
The common thread is ShinyHunters, and it's not just hospitals. The group's Metabase and Snowflake attacks also hit Mathspace, Trezor's shipping vendor ShipMonk, and Carhartt, which lost 12.9 million customer records after refusing to pay a $3.3 million ransom. Same playbook everywhere: get into a vendor's cloud analytics or reporting tool, grab everything, then extort the brand whose name is on the data.
Add IDScan's driver's license mess and Hasbro's employee data leak, and the pattern holds up across industries. Attackers aren't breaking through defenses so much as walking through the side door of some third-party platform nobody was watching closely. If your data lives in someone else's Snowflake, Databricks, or Metabase instance, today's stories are basically a checklist of what can go wrong.
McKesson has confirmed that ShinyHunters breached its Snowflake and Salesforce systems, stealing over 284 million patient records from its Oncology & Multispecialty and Medical-Surgical units, including names, contact details, Social Security numbers, and health information; the group demanded $55.2 million. Separately, Boston Scientific removed attackers from its network but is still investigating a breach that has disrupted activation of new Cardiac Rhythm Management devices implanted after August 25, with no confirmed link to ShinyHunters.
Mathspace, an online math learning platform used in thousands of schools worldwide, disclosed a breach affecting more than 1 million students, parents, and staff after attackers exploited a vulnerability in its self-hosted Metabase reporting system to gain administrator access without credentials. The intrusion began August 10, with data pulled from Australia's reporting database on August 27; only users in Australia and New Zealand had data exposed, and no passwords, academic records, or credentials were taken. The breach follows a wider wave of Metabase attacks tied to the ShinyHunters extortion group, which has also hit Trezor's shipping vendor ShipMonk, Framework, and Tally.
A breach at Trezor's shipping partner ShipMonk now affects 81,000 customers, up from the roughly 14,000 the hardware wallet maker first disclosed in August. ShipMonk failed to delete customer data as required by contract, exposing names, emails, phone numbers, and shipping addresses for 67,000 additional U.S. customers who ordered between November 2019 and August 2021. Breach notifications point to exploitation of a Metabase zero-day, and ShipMonk has reportedly received extortion demands from the ShinyHunters gang; Trezor says its own devices and systems remain secure but warns customers of phishing risk.
Identity verification company IDScan faces multiple lawsuits, filed in Louisiana, after a dark-web service called Nexus allegedly offered more than 153 million U.S. and Canadian driver's license scans, 10 million ID cards, and other documents tied to the company's systems. IDScan has begun notifying business clients such as Hertz, but hasn't confirmed a breach or the number of people affected; the FBI's New Orleans office has opened an investigation.
Baylor Genetics, a US clinical diagnostic lab, disclosed a cyberattack detected around June 15 that exposed data on roughly 2.8 million patients and employees, according to a filing with the Department of Health and Human Services. Stolen data includes names, birth dates, lab test results, health insurance details, and, for a smaller subset, Social Security numbers and financial account information. No group has claimed responsibility, and the company says it has seen no evidence of fraud or misuse so far, with operations continuing normally.
Aesto Health, a healthcare data-migration and archiving vendor, disclosed a breach affecting more than 9.5 million patients after an unauthorized actor accessed its AWS infrastructure between December 2 and December 18, 2025. Exposed data includes names, dates of birth, Social Security numbers, driver's license numbers, health insurance details and medical information; the breach indirectly touches 29 healthcare providers, including VillageMD, Everside Health, Marana Health and Together Women's Health. No threat group has claimed responsibility, and affected individuals are being offered 24 months of identity theft protection through Experian.
Oncology company Novocure disclosed in an SEC filing that attackers accessed its systems in mid-August, exposing ID numbers for more than 1,400 U.S. cancer patients and, for fewer than 50 patients in the western U.S., names and other identifying details along with healthcare provider contact information. The breach also exposed contact details, including job titles and phone numbers, for an undisclosed number of Novocure employees. The company said no treatment devices were accessed and operations remain unaffected, and it is still evaluating notification obligations.
Healthcare company Nutex Health has confirmed hackers stole patient, employee, provider, business, and financial data from its network in a breach disclosed to the SEC. The Gentlemen ransomware group, a RaaS operation with over 580 victims across 75-plus countries, claimed responsibility and threatened to leak the data within nine days. Nutex, based in Houston, also faces a proposed class-action lawsuit filed in Texas over the incident.
The ShinyHunters extortion group leaked 12.9 million Carhartt customer records after the clothing company refused to pay a $3.3 million ransom demand. Security researcher Troy Hunt confirmed the data, taken from Carhartt's Databricks analytics platform, includes names, email addresses, phone numbers, and physical addresses, though some synthetic records not tied to real people were excluded. ShinyHunters, which has claimed breaches at hundreds of Salesforce and Snowflake customers, has largely shifted from ransomware encryption to data theft through vishing and SaaS platform attacks.
Hasbro is notifying current and former employees that a network security incident exposed personal data, including names, addresses, phone numbers, national ID numbers and financial information. A filing with the Massachusetts Attorney General's Office lists 436 residents affected, out of a workforce of roughly 4,600. The breach may be tied to a March cyberattack that cost Hasbro $11 million in cleanup and delayed $25 million in sales; the company says it has no evidence of data misuse and is offering identity protection services.

