ShinyHunters Claims 8.8TB Breach at Amazon One Medical
If you have an account with Amazon One Medical, here’s what is being claimed, and what it would mean for you.
ShinyHunters publicly claimed to have stolen 8.8TB of data from Amazon's One Medical primary care network, which serves over 830,000 patients across 250+ U.S. clinics. The alleged theft includes sensitive healthcare records and patient PII. One Medical has not yet issued a public confirmation or response to the extortion claim.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
A group known as ShinyHunters has publicly claimed responsibility for stealing 8.8 terabytes of data from Amazon One Medical, potentially exposing the personal and medical records of more than 830,000 patients across over 250 clinics in the United States.
Public reporting indicates the alleged breach includes sensitive healthcare records and personally identifiable information. One Medical, the primary care network owned by Amazon, has not yet issued a public confirmation or detailed response to the extortion claim. Available reporting describes the incident as involving patient records and other PII, though full verification of the data set remains pending as of the latest updates.
Scale of the breach
This incident matters because your medical history, address, phone number, date of birth, and other details that identify you and your family could now sit on underground forums. Healthcare data is especially damaging when exposed: it can be used for insurance fraud, prescription scams, or to impersonate you when dealing with doctors, employers, or government agencies. For families, a single breach like this can affect every member listed on shared insurance policies or household accounts.
How one leak spreads
The doxxing and identity-chain implications are serious. Criminals rarely stop at one leaked database. A phone number or email from this healthcare breach can be cross-referenced with credentials from earlier leaks, linking your real identity to social media handles, children’s gaming accounts, or family addresses. Once these connections are mapped, targeted harassment, SIM-swapping, or account takeovers become far easier. Credential leaks of this nature frequently cascade into gaming platforms where children use the same or similar passwords, turning a medical breach into a household-wide exposure.
What to do
- Run a DoxxScan to map every link between your emails, phone numbers, handles, and real identity so you can see exactly what chains exist before criminals exploit them.
- Rotate any password you used for One Medical or related Amazon services anywhere else it appears, then switch to a unique passphrase for each account and enable two-factor authentication through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1 billion+ breach records and more than 100 platforms so the next time your information surfaces you learn within hours instead of months.
- Cover the entire household with DoxxScan family coverage, which includes dependents and children’s gaming accounts that often chain back to the same addresses and family emails.
- Let remediation specialists handle the takedown requests across data brokers and exposed records while you focus on securing your daily accounts.
Why the risk continues
The reality is that one breach rarely stays isolated. Taking deliberate steps now can break the chain before it reaches your family.
Continuous protection offered
DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1B+ breach records and 100+ platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that explicitly protects children’s gaming accounts from the kind of cascading takeovers this incident can trigger.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Stryker Medical Tech Wiper Attack — March 2026
Iran-aligned hacktivists caused mass device wipes across Stryker corporate systems in a geopolitical…
SIA Medical Centre Listed by rhysida Ransomware Group
SIA Medical Centre SIA Medical was established in 1993 and was founded by Dr Martin Sia in Melbourne…
ManageMyHealth 120K Medical Records — December 2025
Medical-records platform ManageMyHealth disclosed a breach affecting ~120,000 patients in December 2…