Extortion gang ShinyHunters this week added Baxter International to its darkweb leak site, publishing what the group claims are 7.1 million Salesforce records — including personally identifiable information — pulled from the medical-device maker'''s customer relationship management tenant. Baxter first acknowledged "unauthorized activity involving certain third-party applications" on August 13, and the crew set an August 17 deadline for ransom talks that Baxter appears not to have met.
Baxter Becomes ShinyHunters''' Latest Healthcare Trophy
Baxter is one of the largest hospital-supply and infusion-pump vendors in the world, and the stolen dataset would represent an unusually granular view of hospital customers, distributors and healthcare partners. In a note on its leak site, ShinyHunters said Baxter "failed to reach an agreement with us despite our incredible patience," and offered a one-click download button for the alleged files. The group has hit multiple health-sector Salesforce tenants in 2026, including DentaQuest, from which it claims 234 GB of data affecting 2.6 million people.

Salesforce Tenants Under Sustained Assault
ShinyHunters has industrialised abuse of connected apps and OAuth grants inside Salesforce tenants for months, chaining social engineering and third-party integrations to exfiltrate CRM data. Recent victims include Carnival Corporation with roughly 6 million records and Hallmark, which the group hit for 1.7 million records after refusing to pay. Earlier this summer the crew was tied to CVE-2026-35273, an Oracle PeopleSoft zero-day, showing an expanding tradecraft that stretches well beyond the Salesforce ecosystem.
What Baxter Customers Should Watch For
Health-system SecOps teams that share Salesforce data with Baxter should hunt for anomalous OAuth token grants, unusual data export events and phishing lures referencing Baxter product lines, since leaked contact data is likely to fuel targeted BEC and vendor-impersonation attacks. The incident also lands just days after Microsoft'''s disclosure of CVE-2026-69836 in Entra ID and CISA'''s recent additions to the Known Exploited Vulnerabilities catalogue, underscoring an unusually intense stretch for identity and SaaS defenders.
Reporting based on coverage from Information Security Media Group and DataBreachToday.
