Aug 23, 2026 · 6 min read
ShinyHunters Leaks 7.1M Baxter Salesforce Records
The extortion crew listed Baxter International on 14 August 2026, set a final deadline of 17 August, and on Wednesday 19 August put a download button beside the entry. Baxter, an $11.2 billion maker of IV solutions and infusion pumps, had already acknowledged unauthorized activity involving third party applications on 13 August.
Baxter got out in front of this one by a single day. Its statement went up on 13 August. The listing appeared on 14 August. In a campaign where victims usually stay silent until the data is already downloadable, that ordering tells you the company knew what was coming.
Key Takeaways
- ShinyHunters claims on its dark web leak site to have published 7.1 million Salesforce records stolen from Baxter International, including personally identifiable information.
- Baxter's 13 August 2026 statement acknowledges "unauthorized activity involving certain third party applications" and says manufacturing, customer operations, patient services and business continuity were not affected.
- Baxter has not named ShinyHunters, has not named Salesforce, and has not confirmed the 7.1 million figure, so the record count remains the attacker's claim rather than a verified number.
- The listing follows ShinyHunters' broader Salesforce extortion campaign, which Google Threat Intelligence attributes to vishing calls that trick employees into authorizing malicious connected apps.
- Baxter is the second medical device and products maker ShinyHunters has claimed in 2026, after a 9 million record claim against Medtronic in April.
What Did ShinyHunters Actually Post?
The gang posted a Baxter entry claiming 7.1 million Salesforce records containing personally identifiable information, then added a download link once its deadline passed. GovInfoSecurity reported that Wednesday's post included a button to download the alleged data, the crew's standard signal that negotiations failed.
All of that is a criminal group's own marketing. Nobody outside the gang has validated the file, and leak site counts inflate routinely because they count rows, not people. One contact can appear in a dozen CRM objects. Treat 7.1 million as an upper bound written by someone with an incentive to make it large.
What Has Baxter Actually Confirmed?
Baxter confirmed unauthorized activity involving certain third party applications and nothing about Salesforce, ShinyHunters, or 7.1 million records. The Deerfield, Illinois company says it activated its response procedures, engaged independent forensic specialists, and is still assessing what information may have been accessed.
One carve out matters more than the reassurance. Baxter says there is no evidence the activity affected its products, connected solutions, or the technologies customers use to deliver patient care. For a company whose infusion pumps sit at bedsides in over 100 countries, that is the sentence hospitals needed. It says nothing about the contact database.
The gap between "operations are fine" and "your records are fine" is where these disclosures live. Baxter's 2025 annual report puts revenue near $11.2 billion across three segments selling into hospitals, surgery centers and home care. A CRM serving that footprint is no small address book.
How Does This Campaign Get Into Salesforce?
Two routes, and neither exploits a flaw in Salesforce itself. The first is voice phishing: an attacker calls an employee posing as internal IT and walks them through Salesforce's own connected app authorization screen until they approve a malicious app, often a rebranded clone of the legitimate Data Loader tool. Google Threat Intelligence tracks that activity as UNC6040 and the follow on extortion as UNC6240, and publishes hardening guidance on it.
The second route is a compromised integration. In August 2025 the crew abused stolen OAuth tokens for the Salesloft Drift chat integration to reach hundreds of downstream Salesforce tenants at once. Microsoft's July 2026 analysis describes both paths and recommends inventorying every connected app scope.
Which route hit Baxter is not public, and the phrase third party applications fits either. We have covered both, including the phone call that got ShinyHunters into Brinks Home. The tell usually shows up in the regulatory filing, not the press statement.
Why Target a Medical Products Maker at All?
Because a medical supplier's CRM is a directory of the people who buy for hospitals. Baxter does not sell IV bags to consumers. Its records describe clinicians, procurement officers, biomedical engineers and group purchasing contacts, each tied to an institution and a purchase history. That beats 7.1 million consumer signups.
Put the number in perspective: 7.1 million records is more than half the population of Illinois, where Baxter is headquartered, pulled from a company with roughly 38,000 employees. About 187 records per employee. Nobody inside Baxter can personally vouch for a list that size, which is why nobody notices when it walks out through an authorized app.
Baxter fits a pattern rather than breaking one. ShinyHunters claimed 9 million records from Medtronic in April 2026, then 218,000 business email addresses from eye care maker Alcon on 11 August, and now Baxter eight days later. The two largest claims total 16.1 million records. The healthcare supply chain is not collateral here. It is a target class.
What This Means for Your Inbox
A dumped CRM is a phishing kit with the research already done. Whoever downloads the Baxter file gets an email address plus the context that makes a message credible: your hospital, the products you ordered, the rep you talk to. A lure referencing a real purchase order for real infusion sets, sent to the person who signed it, does not need to be clever.
Invoice fraud follows for procurement contacts. Credential harvesting follows for clinical staff whose work address doubles as a portal login. Leaked lists also feed the low effort end of the market, as in the sextortion emails built from ShinyHunters leak data, where the only stolen detail the sender had was the address itself.
If you work anywhere in the medical supply chain, treat any Baxter branded message about orders, recalls, invoices or account verification as unverified for the next few months. Do not use its links. Open the supplier portal you already have bookmarked, or call the rep at the number in your own records.
What Should Security and Compliance Teams Do This Week?
If you run a Salesforce tenant, the work is posture, not patching. Pull the connected app inventory and read the OAuth scopes rather than the app names. Revoke anything unused for 90 days, restrict new app authorization to a named admin group, enforce IP range restrictions on API access, and enable export monitoring that flags one session pulling unusual volumes. NIST SP 800-207 is the framework to cite when you ask for budget.
The help desk deserves equal attention, because no SaaS setting fixes vishing. Establish a callback procedure that never runs in the direction of the incoming call, and train staff that no real IT request involves reading a code off an app authorization screen.
Compliance teams face a narrower question: whether any exposed records are protected health information handled for a covered entity, which pulls HIPAA breach notification into scope alongside state law. Sales contact data for hospital buyers generally is not PHI. Patient services data for home therapy programs can be, and that line decides whether this is a notification event or a customer relations one, the ambiguity that ran through the Amgen third party cloud breach.
What to Watch Next
Three signals will resolve this. Whether Baxter's next update names Salesforce, converting the gang's claim into a confirmed vector. Whether the file surfaces in breach notification services, the step that turned Sysco's post deadline dump into 2.7 million searchable addresses. And whether state attorney general filings appear, since those list actual data elements rather than adjectives.
Until then, hold the distinction the headlines keep collapsing. Baxter has confirmed an intrusion. ShinyHunters has claimed a number. Only one of those came from someone with a legal obligation to be accurate.