ShinyHunters Claims 8.8TB Breach at Amazon One Medical
If you were named in this filing, here’s what is being claimed, and what it would mean for you.
ShinyHunters publicly claimed to have stolen 8.8TB of data from Amazon's One Medical primary care network, which serves over 830,000 patients across 250+ U.S. clinics. The alleged theft includes sensitive healthcare records and patient PII. One Medical has not yet issued a public confirmation or response to the extortion claim.
— from the group that posted this listing’s own leak-site posting. This is the group’s claim, quoted verbatim; it is not GalaxyWarden’s reporting and has not been independently verified.
Editor’s note: The claims described below originate from a ransomware group’s leak-site posting and have not been independently verified by GalaxyWarden. A listing of this kind is an assertion made by the group during an extortion attempt. It is not evidence that a breach occurred, and we report it as a claim rather than as a finding.
What’s already out there about you?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Here for work? Check a company domain’s exposure.
A group known as ShinyHunters has publicly claimed responsibility for stealing 8.8 terabytes of data from Amazon One Medical, potentially exposing the personal and medical records of more than 830,000 patients across over 250 clinics in the United States.
Public reporting indicates the alleged breach includes sensitive healthcare records and personally identifiable information. One Medical, the primary care network owned by Amazon, has not yet issued a public confirmation or detailed response to the extortion claim. Available reporting describes the incident as involving patient records and other PII, though full verification of the data set remains pending as of the latest updates.
Advertisement
Know the day any company files a breach.
Every SEC 8-K Item 1.05 and state breach notification — dated, sourced, and delivered by email + a JSON API the day it posts. Track any company, not just the ones in the news.
GalaxyWarden Signals and RecentBreaches share common ownership.
- Every indexed leak tied to your address — all of them, named and dated
- A deeper search of collected breach data — the kinds of your information it holds, where it finds you
- What this kind of incident typically exposes
- A ten-minute lock list written for this kind of organisation
Scale of the breach
This incident matters because your medical history, address, phone number, date of birth, and other details that identify you and your family could now sit on underground forums. Healthcare data is especially damaging when exposed: it can be used for insurance fraud, prescription scams, or to impersonate you when dealing with doctors, employers, or government agencies. For families, a single breach like this can affect every member listed on shared insurance policies or household accounts.
How one leak spreads
The doxxing and identity-chain implications are serious. Criminals rarely stop at one leaked database. A phone number or email from this healthcare breach can be cross-referenced with credentials from earlier leaks, linking your real identity to social media handles, children’s gaming accounts, or family addresses. Once these connections are mapped, targeted harassment, SIM-swapping, or account takeovers become far easier. Credential leaks of this nature frequently cascade into gaming platforms where children use the same or similar passwords, turning a medical breach into a household-wide exposure.
What to do
- Run a DoxxScan to map every link between your emails, phone numbers, handles, and real identity so you can see exactly what chains exist before criminals exploit them.
- Rotate any password you used for One Medical or related Amazon services anywhere else it appears, then switch to a unique passphrase for each account and enable two-factor authentication through an authenticator app rather than SMS.
- Enable continuous DoxxScan monitoring across 13.1 billion+ breach records and more than 100 platforms so the next time your information surfaces you learn within hours instead of months.
- Cover the entire household with DoxxScan family coverage, which includes dependents and children’s gaming accounts that often chain back to the same addresses and family emails.
- Let remediation specialists handle the takedown requests across data brokers and exposed records while you focus on securing your daily accounts.
Why the risk continues
The reality is that one breach rarely stays isolated. Taking deliberate steps now can break the chain before it reaches your family.
Continuous protection offered
DoxxScan by GalaxyWarden delivers continuous monitoring across 13.1B+ breach records and 100+ platforms, AI-powered identity-chain mapping, hands-on remediation by specialists, and full household coverage that explicitly protects children’s gaming accounts from the kind of cascading takeovers this incident can trigger.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove — and removing them is what we do.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
For security and vendor-risk teams: get an alert the day a vendor you watch files a breach with a US regulator or the SEC — the filing itself, dated and sourced, plus an API. GalaxyWarden Signals →
A staff address in a leak usually means a third party was breached, not you — check your own domain’s exposure. Exposure Monitoring →
Report details & sourcing
Related breaches
Stryker Medical Tech Wiper Attack — March 2026
Iran-aligned hacktivists caused mass device wipes across Stryker corporate systems in a geopolitical…
ManageMyHealth 120K Medical Records — December 2025
Medical-records platform ManageMyHealth disclosed a breach affecting ~120,000 patients in December 2…
Crunchbase Massive Personal Records Leak — January 2026
ShinyHunters exfiltrated approximately 2 million records from the business-intelligence platform Cru…