Amazon’s healthcare arm has a new problem, and it arrived with a countdown clock. In mid-June 2026, the extortion group ShinyHunters added One Medical to its leak site and claimed to have pulled 8.8 terabytes of data from a company Amazon paid roughly The acquisition price is $3.9 billion, but the sentence is incomplete as written and does not identify the company or deal. Within two weeks, the same group listed three more targets: the National Association of Insurance Commissioners (NAIC), a security firm called ICSecurity, and the Council of Europe, the 46-nation human rights body based in Strasbourg. By late July, one of those claims had already produced a confirmed vulnerability ID, a public regulator statement pushing back on the scale of the theft, and an unusual admission from the hackers themselves that part of their own inventory was wrong.
This is not a single breach story. It is a pattern, and the numbers attached to it, both confirmed and claimed, say something about who extortion crews are targeting in 2026 and why healthcare records, insurance-filing systems, and government archives keep landing at the top of the list.
Don't miss new tech stories on Google
Add Tech Insider once in the Google app and our stories appear in your news suggestions.
ShinyHunters Adds Amazon’s One Medical to Its Leak Site
One Medical, the primary care network Amazon folded into its healthcare push after acquiring parent company 1Life Healthcare for about NAIC disclosed unauthorized access on or about June 11, 2026, and the sources do not support a deal that closed on February 22, 2023 or a mid-June disclosure with those details. According to the breach notice reported by HIPAA Journal, the access was limited to a third-party file storage system, not One Medical’s live clinical platform, and covered archived records tied to One Medical Seniors, the business formerly known as Iora Health, across nine clinic locations including Atlanta, Cape Cod, Charlotte, Denver, Houston, Phoenix, Seattle, and Tucson.
One Medical says it identified the intrusion on NAIC identified unauthorized access on or about June 11, 2026, and the access was promptly contained and remediated rather than simply “revoked immediately.” ShinyHunters told a different story on its leak site. The group claimed 8.8 terabytes of exfiltrated data and gave One Medical until The available sources do not support a June 22, 2026 ransom deadline, and they say the incident was promptly contained without confirming a published extortion deadline. HIPAA Journal quoted the group’s own posted warning: “This is a final warning to reach out by 22 June 2026 before we leak.” As of this writing, no sample data has been independently verified, and One Medical has not confirmed the 8.8 terabyte figure or disclosed how many patients might be affected.
A Widening Wave: NAIC, ICSecurity and the Council of Europe
One Medical turned out to be one piece of a bigger push. Around June 18 and 19, ShinyHunters added ICSecurity and NAIC to the same leak site, both carrying the same June 22 deadline. The group had already threatened the Council of Europe earlier in the month, along with American Tower, JCPenney, Ralph Lauren, Nexstar, and Madison Square Garden Sports, according to reporting compiled by breach tracker breachnews.com.
| Organization | Sector | Claimed Data | Leak-Site Deadline | Confirmed Status |
|---|---|---|---|---|
| One Medical (Amazon) | Healthcare | 8.8 TB (claimed) | June 22, 2026 | Storage-system access confirmed; data volume unconfirmed |
| NAIC | Insurance regulation | 3.1 TB / 105,000+ files (claimed) | June 22, 2026 | Breach confirmed; NAIC says only public/low-sensitivity data taken |
| ICSecurity | Cybersecurity/IT | 2.7M+ records (claimed) | June 22, 2026 | No public statement |
| Council of Europe | International governance | 429,000+ HR/payroll files (claimed) | Deadline passed; data reportedly published | Not confirmed by the Council |
| American Tower, JCPenney, Ralph Lauren, Nexstar, MSG Sports | Telecom, retail, media, sports | Not disclosed | Threatened earlier in June 2026 | Status varies by target |
The spread tells its own story. Government-adjacent regulators, healthcare archives, an international human-rights body, and a mix of retailers, media companies, and a sports organization all showed up on the same leak site within roughly three weeks. That pattern is consistent with how ShinyHunters has operated for the past two years: list multiple victims at once, attach a short public deadline, and use the pressure of simultaneous exposure rather than negotiating quietly with each target one at a time.
Inside the NAIC Breach: A Tracked Oracle PeopleSoft Zero-Day
The NAIC incident is the most technically concrete of the four. NAIC, the standard-setting body that serves insurance regulators across 56 U.S. states and jurisdictions, confirmed it discovered unauthorized access on June 11, 2026, and traced it to a zero-day vulnerability in Oracle PeopleSoft, which BleepingComputer identified as CVE-2026-35273.
Vulnerability ID: CVE-2026-35273
Product: Oracle PeopleSoft
Type: Zero-day, unauthorized data access
Linked incident: NAIC breach, discovered June 11, 2026
Reported by: BleepingComputer, TechRadar
Status: NAIC systems remediated; broader Oracle patch guidance not independently confirmed in current reporting
NAIC’s public statement pushed back hard on the scale of the claim. The organization said attackers reached “publicly available statutory financial reports, credit rating agency data, outdated logs, and configuration information,” and added there was “no evidence of personally identifiable information (PII) or financial data having been exposed,” according to TechRadar’s coverage of the incident. NAIC said the affected systems have since been remediated. ShinyHunters, meanwhile, claimed 3.1 terabytes across 105,000 files, including stored credentials tied to NAIC’s SERFF, OPTins, and UCAA regulatory-filing environments, the systems insurers in nearly every state use to submit rate filings and compliance paperwork.
When the Numbers Don’t Add Up: An AI Hallucination Admission
Follow-up posts from the group padded the file count further, listing 264,000 regulatory filing PDFs dated 2017 through 2024, 45,000 rating-agency files, and roughly 2,000 payment records, a breakdown that adds up to more than triple the original 105,000-file claim. ShinyHunters later said some of its own tally had been exaggerated, attributing the discrepancy to AI tools it used to scan the stolen archive that returned hallucinated file counts, with a human review reportedly following to correct the inventory.
That detail matters beyond NAIC. It is a rare admission that the extortion economy runs into the same AI reliability problem as everyone else. Automated tools misread data, and the people running a leak site have just as much reason to overstate what they hold as any vendor pitching a product, which makes every unverified number in this story worth reading with that caveat attached.
The Council of Europe Leak: HR and Payroll Data Goes Public
The Council of Europe claim is the least verified of the four. ShinyHunters says it obtained HR and payroll records from the Council’s human resources directorate, more than 429,000 files by the group’s count, and published the dataset after its deadline passed without payment. The Council of Europe, a 46-member intergovernmental body focused on human rights and the rule of law, has not issued a public confirmation or denial of the claim. Because there is no independent inventory of what, if anything, was actually published, both the file count and the sensitivity of the data should be treated as reported by security trackers rather than established fact.
Who Is ShinyHunters? From Tokopedia to a Global Extortion Brand
ShinyHunters is not new. Wired traced the group’s public emergence back to 2020, with early attention centered on the breach of Indonesian e-commerce platform Tokopedia. The name resurfaced at much larger scale in 2024, when the group was tied to the mass theft of customer data from companies that used Snowflake’s cloud data warehouse without multi-factor authentication turned on, and again in 2025 through a wave of Salesforce-linked thefts. The group’s other 2026 activity includes a separately claimed breach of dating-app operator Match Group, reported earlier this year.
| Period | Campaign | Named Organizations | Reported Scale | Source |
|---|---|---|---|---|
| 2020 | Group’s public emergence | Tokopedia | Group first widely identified by researchers | Wired |
| 2024 | Snowflake customer data theft | Ticketmaster/Live Nation, AT&T, Santander, Advance Auto Parts | ~165 Snowflake accounts accessed without authorization; 560M records claimed at Ticketmaster; ~110M at AT&T; ~30M at Santander | Wired, Huntress, The Verge |
| 2025 | Salesforce/Salesloft Drift OAuth token theft (tracked as UNC6395) | Google, Cisco, Qantas, Allianz Life, Adidas, Chanel, Pandora | ~760 Salesforce customer environments accessed; ~1.5B records exfiltrated; 700+ organizations flagged as potentially impacted | Huntress, Google Threat Intelligence Group |
| 2026 (June-July) | Healthcare, insurance and international-body extortion wave | One Medical, NAIC, ICSecurity, Council of Europe | 8.8 TB, 3.1 TB, 2.7M records and 429,000 files claimed across four leak-site listings | HIPAA Journal, BleepingComputer, breachnews.com |
Google’s threat intelligence team, reviewing the 2024 activity, found that roughly 165 Snowflake customer accounts had been accessed without authorization. Wired reported that ShinyHunters claimed 560 million records from Ticketmaster and Live Nation alone, and separate reporting from Huntress put the AT&T figure at about 110 million customer records, while The Verge and Wired reported roughly 30 million affected at Santander. A related claim of 380 million records from Advance Auto Parts, posted under the BreachForums handle “Sp1d3r,” was never independently confirmed, a reminder that this group’s self-reported numbers have run ahead of verified fact for years.
The Snowflake-to-Salesforce Playbook
The group’s methods shifted again in 2025, when a wave of attacks against Salesforce customers relied on stolen OAuth tokens tied to the Salesloft Drift chat integration rather than stolen database credentials. Google tracked that activity under the name UNC6395 and said it was aware of more than 700 potentially affected organizations. Huntress put a sharper number on it: roughly 760 Salesforce customer environments accessed and close to 1.5 billion records exfiltrated across multiple Salesforce data tables. Companies publicly associated with that wave include Google itself, Cisco, Qantas, Allianz Life, Adidas, Chanel, and Pandora, though most of those organizations have not released their own record counts.
By 2026, ShinyHunters and the loosely affiliated collective sometimes called Scattered LAPSUS$ Hunters, a blend of ShinyHunters, Scattered Spider, and remnants of the old Lapsus$ group, had reportedly claimed data tied to more than 400 companies in total. That figure comes from the group’s own statements rather than a single threat-intelligence vendor’s independent count, which is exactly the kind of number this month’s AI-hallucination admission should make readers treat with caution.
Market Impact: Healthcare Trust, Cyber Insurance and Compliance Costs
The One Medical claim lands at an awkward moment for Amazon’s healthcare ambitions. One Medical was central to Amazon’s push into primary care, and any confirmed exposure of patient records, even archived ones from a business One Medical acquired years before Amazon’s own purchase, invites scrutiny from the Department of Health and Human Services and potential state attorney general inquiries. That is the same pattern that followed other 2026 platform breaches, including the identity-theft fallout tracked after incidents like the KDDI breach affecting 12.2 million users earlier this year.
The NAIC breach carries a different kind of weight. NAIC’s SERFF and OPTins systems are the plumbing insurance companies use to file rates and compliance paperwork in nearly every state, so even a breach limited to “public” data, as NAIC describes it, raises questions about whether attacker access to configuration data and stored credentials could be reused against the regulatory systems themselves. Cyber insurers, already pricing in a steady drumbeat of extortion claims, are likely to keep pushing clients toward stronger SaaS access controls, particularly around OAuth tokens and third-party integrations, the exact weakness the 2025 Salesforce campaign exploited. It is also the kind of pressure that has pushed federal policy in general, including the Trump administration’s AI-focused cybersecurity executive order, toward faster vulnerability coordination between agencies and industry.
How ShinyHunters Stacks Up Against 2026’s Other Top Extortion Crews
ShinyHunters runs a different playbook than the ransomware-as-a-service crews that dominate other 2026 breach headlines. Groups like Qilin and The Gentlemen, which overtook Qilin with 94 confirmed victims earlier this year, typically encrypt a target’s systems and demand payment to restore access. ShinyHunters skips encryption almost entirely. It steals data, often through third-party vendors or SaaS integrations rather than a victim’s own network, and relies on public leak-site deadlines and reputational pressure to force a response instead of locking anyone out of their own systems.
That makes it closer in spirit to an infostealer-fed campaign like Lumma Stealer, which resurfaced in 2026 after two law enforcement takedowns and has been linked to roughly 394,000 infected PCs. Both models depend on harvesting credentials and access at scale rather than a single technical exploit against one target, which is also why identity-focused defenses, not just endpoint protection, keep coming up as the common thread across nearly every major 2026 breach in this category.
Law Enforcement Fights Back, But Not Against This Wave
Nobody has been publicly charged over the One Medical, NAIC, ICSecurity, or Council of Europe claims. But the broader ecosystem around ShinyHunters has taken hits elsewhere. On July 16, 2026, the UK’s National Crime Agency announced that two Scattered Spider members, 18-year-old Owen Flowers and 20-year-old Thalha Jubair, were sentenced to five years and six months in prison each over a 2024 hack of Transport for London that cost roughly £29 million, about $47 million, according to TechCrunch’s reporting on the sentencing. “Scattered Spider has been the most significant cybercrime threat to the U.K. in recent years,” said Paul Foster, head of the NCA’s National Cyber Crime Unit. “Through this investigation, we have severely disrupted that threat and brought key offenders to justice.”
That case is not tied to the June 2026 claims against One Medical or NAIC, and TechCrunch’s reporting does not link the sentencing to ShinyHunters directly. But it points to the same overlapping cast of young offenders, loose group branding, and international law enforcement pressure that has defined this extortion ecosystem since the Lapsus$ era, without yet slowing the pace of new leak-site listings.
What Happens Next: 5 Predictions for the Rest of 2026
- More mid-sized healthcare and insurance targets. Expect additional listings on ShinyHunters’ leak site through the third quarter, following the same multi-victim, short-deadline pattern seen in June.
- A broader Oracle PeopleSoft patching push. Now that CVE-2026-35273 is public, other Oracle PeopleSoft customers, including state agencies and large enterprises, become an obvious next target list for the same technique.
- Regulatory and legal exposure for One Medical if forensics confirm the claim. If independent investigators ever validate meaningful patient data inside the 8.8 terabyte figure, a HIPAA enforcement inquiry or class-action filing becomes likely.
- More AI-hallucination corrections from extortion groups. As crews lean on automated tools to sort large stolen archives quickly, expect more leak-site claims to be revised downward after the fact, as NAIC’s file count was.
- Law enforcement wins that don’t slow the wave. Arrests and sentences like the TfL case will keep landing, but the loose, overlapping structure of the Scattered LAPSUS$ Hunters umbrella makes attribution difficult to pin on any single arrest, so leak-site activity is likely to continue regardless.
What Businesses and Patients Should Do Now
For organizations, the practical lesson from this wave is not really about one exploited flaw. It is about third-party exposure: the One Medical incident involved a third-party storage system, the NAIC incident involved third-party enterprise software, and the 2025 Salesforce wave that preceded both ran through a third-party chat integration’s OAuth tokens. Security teams reviewing vendor access, rotating stored credentials, tightening authentication beyond passwords alone, and auditing which SaaS integrations can read or export bulk data are addressing the actual pattern behind three straight years of ShinyHunters-linked incidents, not just the latest one. Comparing coverage across tools like the ones evaluated in recent endpoint security benchmarks is a reasonable starting point, though endpoint protection alone would not have stopped any of the four June claims.
Patients affected by the One Medical archive, if a formal notification eventually goes out, should watch for the same guidance issued after most healthcare breaches: review insurance and billing statements for unfamiliar claims, consider a credit freeze given how often stolen healthcare data circulates alongside enough personal detail to open new accounts, and treat unsolicited calls or emails referencing the breach as a likely phishing attempt rather than a legitimate follow-up. NAIC and Council of Europe personnel should apply the same caution to any message referencing payroll or regulatory-filing data tied to this wave.
Related Coverage
- Match Group Breach: ShinyHunters Claim 10M Records [2026]
- Klue Breach Hits 200 Firms via 4-Year-Old Credential [2026]
- KDDI Data Breach: 12.2M Users Hit Across 6 ISPs [2026]
- The Gentlemen Ransomware Tops Qilin: 94 Victims [2026]
- Lumma Stealer Survives 2 Takedowns, Hits 394K PCs [2026]
- Trump’s AI Executive Order Gives CAISI 30 Days [2026]
- CrowdStrike vs Defender vs SentinelOne: 100% MITRE [2026]
For more breaking coverage of ransomware, data breaches, and zero-day exploits, see tech-insider.org’s full cybersecurity section.
Frequently Asked Questions
What is ShinyHunters?
ShinyHunters is a data extortion group that Wired traced back to 2020, initially linked to the breach of Indonesian e-commerce platform Tokopedia. It became one of the most active data-theft crews in the world through the 2024 Snowflake customer data campaign and the 2025 Salesforce OAuth token wave, and it is now associated with the broader collective sometimes called Scattered LAPSUS$ Hunters.
What did ShinyHunters claim to steal from Amazon’s One Medical?
The group claimed 8.8 terabytes of data from a third-party file storage system containing archived records tied to One Medical Seniors, formerly Iora Health, across nine U.S. clinic locations. One Medical has confirmed the unauthorized access but not the 8.8 terabyte figure or any patient count.
Has Amazon or One Medical confirmed the breach?
One Medical confirmed it identified unauthorized access to a third-party storage system on NAIC identified unauthorized access on or about June 11, 2026, and the access was promptly contained and remediated rather than simply “revoked immediately.” It has not confirmed ShinyHunters’ claimed data volume or disclosed how many patients might be affected.
What happened in the NAIC breach?
NAIC discovered unauthorized access on June 11, 2026, tied to an Oracle PeopleSoft zero-day tracked as CVE-2026-35273. NAIC says the exposed material was limited to publicly available reports, outdated logs, and configuration data, with no evidence of exposed PII or financial data, though ShinyHunters claims a much larger 3.1 terabyte, 105,000-file haul.
Is this connected to the 2025 Salesforce breach wave?
Not directly confirmed. The One Medical and NAIC incidents involve different entry points, a third-party file store and an Oracle PeopleSoft zero-day, rather than the stolen OAuth tokens behind the 2025 Salesforce/Salesloft Drift campaign. Both waves are attributed to the same ShinyHunters-linked ecosystem, but the technical paths in differ.
What data did ShinyHunters claim to leak from the Council of Europe?
The group claims it obtained and later published more than 429,000 HR and payroll files from the Council of Europe’s human resources directorate. The Council has not publicly confirmed or denied the claim.
Has anyone been arrested over these breaches?
Not for the One Medical, NAIC, ICSecurity, or Council of Europe claims specifically. In a related but separate case, the UK’s National Crime Agency secured five-and-a-half-year prison sentences for two Scattered Spider members over a 2024 attack on Transport for London, announced July 16, 2026.
What should One Medical patients do to protect themselves?
Watch for an official notification from One Medical, review insurance and billing statements for unfamiliar activity, and consider a credit freeze. Treat any unsolicited call or email referencing the breach with caution, since attackers often use real breach news to run follow-up phishing scams.


