ShinyHunters Claims Baxter Breach, Publishes Cook Medical, Carhartt and Sharecare Data

ShinyHunters has named Baxter, Cook Medical, Carhartt, and Sharecare in new breach claims, publishing alleged data from three of the companies.
Screenshot of the ShinyHunters leak site showing new listings for Baxter International, Cook Medical, Carhartt, and Sharecare, including an extortion warning for Baxter, downloadable data archives for the other companies, and a notice stating additional leaks are forthcoming.
ShinyHunters’ leak site lists new alleged victims including Baxter International, Cook Medical, Carhartt, and Sharecare. The group claims Baxter remains under a pay-or-leak deadline while alleged data archives for the other three organizations have already been published.

ShinyHunters has added Baxter International, Cook Medical, Carhartt, and Sharecare to its latest wave of extortion activity, claiming to have stolen millions of Salesforce records and hundreds of gigabytes of internal corporate data across the four organizations.

The group has already published alleged data from Cook Medical, Carhartt, and Sharecare, while Baxter remains under a “pay or leak” warning with an August 17, 2026 deadline. ShinyHunters also posted a broader notice warning that additional leaks are coming as the group deals with what it described as an influx of victims.

Baxter faces August 17 leak deadline

ShinyHunters claims to have compromised more than 7.1 million Salesforce records belonging to Baxter International, with some records allegedly containing personally identifiable information.

Unlike the other three newly disclosed victims, Baxter’s alleged data has not yet been published. The group has instead issued a final warning giving the company until August 17 to make contact before the purported data is released and additional digital disruption is threatened.

The listing does not specify which categories of PII are allegedly included in the Salesforce records, nor does it provide a size for the purported dataset.

Cook Medical archive published after alleged negotiations

ShinyHunters has also published what it claims is more than 182 GB of compressed data stolen from Cook Medical. According to the group, the material includes customer information, employee information, and other internal corporate data.

The group claims Cook Medical previously engaged in negotiations but that the parties failed to reach an agreement over the payment demand. ShinyHunters alleges that it subsequently published the data after rejecting the company’s offers.

No detailed record count or breakdown of the specific customer and employee fields was provided in the leak-site description.

Carhartt data posted after $3.3 million demand

Carhartt was also moved into the publication stage, with ShinyHunters claiming that its original extortion demand was $3.3 million.

The group alleges that millions of customer records were compromised alongside employee information, customer metadata, loyalty-related information, and other sensitive internal corporate data. The published archive is listed at more than 50 GB compressed.

ShinyHunters claims Carhartt made contact but ultimately declined to continue negotiations. The group included purported negotiation correspondence in its listing to support that account, although BreachNews has not independently verified the exchange.

Sharecare claim includes 3.4 million Salesforce records

ShinyHunters separately claims to have obtained more than 3.4 million Salesforce records from digital health company Sharecare, with some allegedly containing PII, along with more than 28 GB of internal corporate information.

The data published by the group is listed at more than 25 GB compressed. ShinyHunters again attributed publication to failed negotiations, claiming the company and its representatives did not reach an agreement before the data was released.

The leak-site entry does not identify the exact PII fields allegedly contained in the Salesforce records.

ShinyHunters warns more leaks are coming

Alongside the new victim listings, ShinyHunters posted a warning stating that it is currently handling increased activity and that additional data releases are on the way. The group also threatened to accelerate publication when organizations or negotiators are perceived as delaying discussions.

The latest activity follows the group’s recent publication of an alleged 7.1 GB Metabase archive. That listing provided almost no information about the purported breach or contents of the archive, while the group’s newer victim entries include considerably more detail about alleged data volumes and negotiation activity.

BreachNews continues to track ShinyHunters’ extortion activity, victim listings, data releases, and related campaigns in its ShinyHunters threat actor profile.

The Baxter, Cook Medical, Carhartt, and Sharecare claims have not been independently verified by BreachNews. The presence of downloadable archives for three of the organizations shows that ShinyHunters is distributing data it attributes to those companies, but does not by itself establish the authenticity, completeness, or origin of the files.

Picture of m00s3c

m00s3c

Moose (@m00s3c) is the author of BreachNews, focusing on data breach intelligence, dark web monitoring, and threat analysis. His work involves analyzing breach claims, reviewing leaked datasets, and tracking threat actor activity to provide clear, factual reporting.

Latest News

BREACHNEWS.COM/SUPPORT/

Support Independent News.

Help support breach monitoring, investigations, infrastructure, and reporting.

Support the site