Carhartt data breach affects 12.9M, half of what ShinyHunters claimed
One AI and two trained eyes delved into the heavily padded leaks
ShinyHunters claims to have stolen 284 million patient records from McKesson, a major U.S. healthcare distributor, following unauthorized access to third-party applications. McKesson detected the intrusion on August 25, 2026, and stated the investigation is in its early stages with materiality still being assessed.
Read full article at Help Net Security ↗One AI and two trained eyes delved into the heavily padded leaks
ReliaQuest has responded to compromise claims following a social engineering attack attributed to ShinyHunters, asserting that the threat actor did not successfully breach its systems. The company has provided details about the attack method while refuting reports suggesting a full compromise occurred.
ReliaQuest confirmed that one of its employees fell victim to a social engineering attack that provided attackers with a password and temporary access to the company's identity system. Extortion group ShinyHunters subsequently posted screenshots on its leak site, claiming responsibility and taunting the cybersecurity firm over the breach. The incident followed an earlier exchange between ShinyHunters and ReliaQuest's threat research team on social media.
ReliaQuest has confirmed that threat actor ShinyHunters exploited a phishing attack against an employee to gain access to a dashboard within the company's systems. The company claims that the scope of the breach was limited, though the specific data accessed or exposed was not detailed in the report.