Contractor account breach exposes data of 4.1 million patients
This is a Daily Cyber dot News update, brought to you by Bare Metal Cyber dot com, for Thursday, September 10th, 2026.
The immediate consequence is a serious loss of patient trust. Sensitive data tied to 4.1 million people was exposed after attackers entered AdaptHealth’s cloud-based business applications. The intrusion reached patient management systems, document storage platforms, and electronic health record portals. AdaptHealth said the entry point was a social engineering attack that compromised a privileged account belonging to a third-party contractor. An unnamed actor later demanded payment, although the company said it had found no evidence of identity theft, fraud, or misuse.
That doesn’t remove the longer-term risk. Stolen private data can remain useful for phishing and identity attacks well after notifications are sent. Leaders should treat third-party privileged accounts with the same ownership, review, and accountability applied to internal administrators. Defenders should monitor contractor sessions, limit access to the work being performed, and revoke unusual cloud activity quickly. The practical step now is to audit every privileged contractor account and immediately reduce any access that’s broader than the current business need.
For the sources and the full Daily Cyber newsletter, visit Daily Cyber dot news.