Ransomware victim disclosure
← All victimsOne Medical
listed as Amazon owned OneMedical.com · Claimed by Shinyhunters · listed 9 hours ago
Status timeline
- ListedJun 18, 2026
- Data leakeddate unknown
At a glance
- Group
- Shinyhunters
- Status
- Data leaked
- Country
- United States
- Sector
- Healthcare
- Listed on leak site
- Jun 18, 2026
About the victim
AI dossier — public-source company profileOne Medical is a primary care provider owned by Amazon that operates a network of medical offices and provides digital healthcare services to patients in the United States. The company combines in-person and telemedicine care.
- Industry
- Healthcare Services & Digital Health
- Founded
- 2007
Attack summary
Severity: critical — Alleged exfiltration of 8.8TB from a major healthcare provider indicates large-scale compromise of patient PHI and medical records. Healthcare data is regulated (HIPAA) and highly sensitive. The scale and sensitivity trigger critical classification despite lack of visible proof inventory.Threat actor claims to have exfiltrated 8.8TB of data from One Medical/Amazon. The group issued a ransom demand with a final deadline of 22 June 2026, threatening to publish the data if payment was not made.
Data the group says was taken
AI dossier — extracted from the leak post- Patient medical records
- Personal health information (PHI)
- Patient contact information
- Healthcare billing data
What the group claims
Over 8.8TB of data was compromised. This is a final warning to reach out by 22 June 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 18 June 2026 | Warning: FINAL WARNING PAY OR LEAK
Source
Indexed 9 hours agoThis page surfaces a public ransomware disclosure indexed by Darkfield. Original posts come from the operator's own leak site; we cross-check against ransomware.live, RansomLook and RansomWatch where applicable. Share this URL freely.
Is this your supplier? Your competitor? You?
Pro plans monitor your domain, corporate emails, and crypto wallets across every new ransomware leak-site post, breach dump and Telegram callout — alerts within 5 minutes.

