Baxter International data breach (ShinyHunters)
After Baxter International declined to meet an extortion deadline, the ShinyHunters group published a data set it said contained 7.1 million records stolen from the medical-device maker's Salesforce environment through a third-party application compromise.
- Victim
- Baxter International Inc.
- records
- 7.1M
On 19 August 2026, the extortion group ShinyHunters published a data set it claimed contained 7.1 million records stolen from Baxter International Inc. โ the Illinois-based global medical-device and hospital-products manufacturer โ after the company declined to meet an extortion deadline. The records were reportedly exfiltrated from Baxter's Salesforce customer-relationship environment via a compromise of third-party applications.
Baxter first disclosed on 13 August 2026 that it had found unauthorized activity involving certain third-party applications. ShinyHunters listed the company on its leak site the next day, set a 17 August payment deadline, and released the data on 19 August when that deadline passed. The incident fits a broader 2026 wave in which ShinyHunters targeted enterprises' Salesforce and connected SaaS applications for mass data theft and extortion.
What happened
Baxter's public statements were deliberately narrow: the company confirmed unauthorized activity involving third-party applications but did not confirm the nature or volume of the stolen data. It stressed that manufacturing, customer operations, patient services and business continuity were all unaffected, and that healthcare providers could continue to use Baxter products as intended.
ShinyHunters, for its part, claimed 7.1 million Salesforce records were exfiltrated, some containing personally identifiable information. As security reporting noted, a claimed 7.1 million records does not necessarily equate to 7.1 million distinct people affected โ CRM exports often contain duplicate, contact-level or business-account rows โ so the true count of impacted individuals remained unverified at disclosure.
Impact
- ShinyHunters published a data set it says holds 7.1 million records drawn from Baxter's Salesforce environment, some with personal data.
- Baxter reported no impact to manufacturing, customer operations or patient services, and no disruption to product availability.
- The true number of affected individuals was unconfirmed; the exposed CRM data raises phishing and social-engineering risk for Baxter's contacts and customers.
Why it matters
The Baxter case is another entry in ShinyHunters' 2026 campaign against Salesforce and connected SaaS applications, in which the target is not the core enterprise system but the data lake that CRM platforms accumulate. For a medical-device maker, the exposed CRM likely maps relationships across hospitals, distributors and clinical customers โ a directory well suited to targeted fraud even without patient records. The incident again shows that refusing to pay does not prevent disclosure once an attacker has already exfiltrated the data, and that SaaS supply-chain exposure now sits alongside on-premises intrusion as a primary breach vector.
Timeline
Baxter discloses it found unauthorized activity involving certain third-party applications.
ShinyHunters adds Baxter to its dark-web leak site, claiming responsibility for the theft.
ShinyHunters sets an extortion deadline, threatening to leak the stolen data if unpaid.
After the deadline passes without payment, ShinyHunters releases the stolen data, which it says totals 7.1 million Salesforce records.
Sources
- hipaajournal.comhttps://www.hipaajournal.com/shinyhunters-baxter-international-data-breach/
- govinfosecurity.comhttps://www.govinfosecurity.com/shinyhunters-leaks-71-million-baxter-international-records-a-32630
- paubox.comhttps://www.paubox.com/blog/shinyhunters-leaks-7.1-million-records-from-baxter-crm