Ransomware victim disclosure
← All victimsBaxter International, Inc.
Claimed by Shinyhunters · listed 4 days ago
Status timeline
- ListedAug 14, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Aug 14, 2026
About the victim
AI dossier — public-source company profileBaxter International is a global healthcare company providing connected solutions, medical devices, and injectable medicines across hospital, physician office, and other care settings. The company serves millions of patients and healthcare providers daily with products spanning infusion therapies, surgical technologies, diagnostics, pharmaceuticals, and respiratory devices.
- Industry
- Healthcare – Medical Devices & Injectable Medicines
Attack summary
Severity: critical — Confirmed exfiltration of PII at significant scale (7.1 million records) from a major regulated healthcare company. Healthcare data involving millions of individuals triggers critical classification regardless of proof publication status.The threat actor claims to have compromised 7.1 million Salesforce records containing personally identifiable information (PII). The group issued a final warning dated 14 August 2026 with a deadline of 17 August 2026, threatening data publication and unspecified additional disruption if contact is not made.
Data the group says was taken
AI dossier — extracted from the leak post- Salesforce records
- Personally identifiable information (PII)
What the group claims
Over 7.1M Salesforce records containing some PII was compromised. This is a final warning to reach out by 17 Aug 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 14 Aug 2026 | Warning: FINAL WARNING PAY OR LEAK
Sources
- Victim sitebaxter.com
Source
Indexed 4 days agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

