ShinyHunters has added Baxter International, Cook Medical, Carhartt, and Sharecare to its latest wave of extortion activity, claiming to have stolen millions of Salesforce records and hundreds of gigabytes of internal corporate data across the four organizations.
The group has already published alleged data from Cook Medical, Carhartt, and Sharecare, while Baxter remains under a “pay or leak” warning with an August 17, 2026 deadline. ShinyHunters also posted a broader notice warning that additional leaks are coming as the group deals with what it described as an influx of victims.
Baxter faces August 17 leak deadline
ShinyHunters claims to have compromised more than 7.1 million Salesforce records belonging to Baxter International, with some records allegedly containing personally identifiable information.
Unlike the other three newly disclosed victims, Baxter’s alleged data has not yet been published. The group has instead issued a final warning giving the company until August 17 to make contact before the purported data is released and additional digital disruption is threatened.
The listing does not specify which categories of PII are allegedly included in the Salesforce records, nor does it provide a size for the purported dataset.
Cook Medical archive published after alleged negotiations
ShinyHunters has also published what it claims is more than 182 GB of compressed data stolen from Cook Medical. According to the group, the material includes customer information, employee information, and other internal corporate data.
The group claims Cook Medical previously engaged in negotiations but that the parties failed to reach an agreement over the payment demand. ShinyHunters alleges that it subsequently published the data after rejecting the company’s offers.
No detailed record count or breakdown of the specific customer and employee fields was provided in the leak-site description.
Carhartt data posted after $3.3 million demand
Carhartt was also moved into the publication stage, with ShinyHunters claiming that its original extortion demand was $3.3 million.
The group alleges that millions of customer records were compromised alongside employee information, customer metadata, loyalty-related information, and other sensitive internal corporate data. The published archive is listed at more than 50 GB compressed.
ShinyHunters claims Carhartt made contact but ultimately declined to continue negotiations. The group included purported negotiation correspondence in its listing to support that account, although BreachNews has not independently verified the exchange.
Sharecare claim includes 3.4 million Salesforce records
ShinyHunters separately claims to have obtained more than 3.4 million Salesforce records from digital health company Sharecare, with some allegedly containing PII, along with more than 28 GB of internal corporate information.
The data published by the group is listed at more than 25 GB compressed. ShinyHunters again attributed publication to failed negotiations, claiming the company and its representatives did not reach an agreement before the data was released.
The leak-site entry does not identify the exact PII fields allegedly contained in the Salesforce records.
ShinyHunters warns more leaks are coming
Alongside the new victim listings, ShinyHunters posted a warning stating that it is currently handling increased activity and that additional data releases are on the way. The group also threatened to accelerate publication when organizations or negotiators are perceived as delaying discussions.
The latest activity follows the group’s recent publication of an alleged 7.1 GB Metabase archive. That listing provided almost no information about the purported breach or contents of the archive, while the group’s newer victim entries include considerably more detail about alleged data volumes and negotiation activity.
BreachNews continues to track ShinyHunters’ extortion activity, victim listings, data releases, and related campaigns in its ShinyHunters threat actor profile.
The Baxter, Cook Medical, Carhartt, and Sharecare claims have not been independently verified by BreachNews. The presence of downloadable archives for three of the organizations shows that ShinyHunters is distributing data it attributes to those companies, but does not by itself establish the authenticity, completeness, or origin of the files.










