Executive Risk & Board Advisory

Amazon's One Medical Confirms a "Limited" Breach. ShinyHunters Claims 8.8 Terabytes and a Deadline. Only One of Those Is Verified.

Blog Meta Icon
Dipan Mann
Founder, CEO & CTO
Blog Meta Icon
June 21, 2026
Blog Meta Icon
11 minute read
Blog Main Image

One Medical, the primary care network Amazon bought for 3.9 billion dollars, has confirmed a "limited" breach of a legacy storage system. The same week, the extortion group ShinyHunters claims it stole 8.8 terabytes and set a June 22 deadline. One of those descriptions is wrong, and right now no one outside the negotiation can prove which.

There are two numbers in public right now describing what happened to One Medical, and they describe two different incidents.

The first comes from the company. On June 13, 2026, One Medical learned that an unauthorized party had accessed a third-party file storage system used to retain archived records from legacy Iora Health patients, the senior-focused practice Amazon’s One Medical acquired in 2021 and now operates as One Medical Seniors. The company’s investigation determined that the access ran from roughly June 8 through June 11, and that the files involved a subset of demographic and clinical records from patients at a specific set of One Medical Seniors clinics: Atlanta, Cape Cod, Charlotte, Piedmont Triad, Denver, Houston, Phoenix, Tucson, and Seattle. One Medical says it deactivated the system and revoked access immediately, that the incident was isolated to that third-party storage environment, and that no other One Medical or Amazon systems were affected. Affected patients are being notified.

That is the careful, scoped, lawyer-reviewed version. A limited number of files. A legacy system. A named, finite list of clinics. Everything in the disclosure is designed to draw a tight box around the problem.

The second number comes from the people on the other side of the keyboard. On June 18, the extortion group ShinyHunters listed One Medical on its dark-web leak site and claimed it had stolen 8.8 terabytes of data. It issued what it called a final warning, giving the company until June 22 to begin negotiations, and promised, in its own words, to publish the data “along with several annoying digital problems that’ll come your way” if One Medical does not engage.

8.8 terabytes is not a limited number of files. It is an entire records environment.

So which is it? Here is the honest answer, and it is the entire point of this post: as of right now, no one outside the negotiation can prove it either way. ShinyHunters has released no sample data to substantiate the 8.8-terabyte figure. One Medical has confirmed only the storage incident it found. The two statements cannot both be a complete description of the same event, and the gap between them is where every decision a board has to make this week actually lives.

💡 Key Insight

There are two numbers in public right now for the same healthcare provider, and they are not close. The job before the deadline is not to pick one. It is to verify which one the evidence supports.

This is not a new shape. It is the exact shape of the Canvas/Instructure breach Cloudskope documented in May, and it is the same threat actor.

In that incident, Instructure called an active ransom defacement scheduled maintenance, called the intrusion contained the day after the criminals first demonstrated access, and called it resolved with Canvas fully operational twenty-four hours before every major university Canvas page in North America redirected to a live extortion message. The company kept describing the smallest defensible version of events. ShinyHunters kept demonstrating a larger one. The truth was not in the middle. It was on the criminals’ side of the gap, and the institutions that believed the company’s framing lost a week they could have spent notifying people.

ShinyHunters runs a pay-or-leak model. The group has been active since at least 2019, it steals data rather than encrypting it, and its leverage is publication. It has been tied to Ticketmaster, AT&T, and Okta, and in 2026 alone it has worked through a long victim list: the Canvas/Instructure education breach, the Infinite Campus K-12 student information system, DentaQuest, Madison Square Garden Entertainment, Kodak, and 7-Eleven, among others. Removing a victim from the leak site usually signals that negotiations have started, not that the threat was fake.

That track record cuts in a specific direction here. It does not prove the 8.8-terabyte claim. ShinyHunters has inflated numbers before, and an unverified extortion claim with no sample is exactly the kind of thing that deserves skepticism, not a headline. But the group’s history means the claim cannot be waved away either. A board that treats “no sample data yet” as “probably nothing” is making the same bet Instructure’s customers made when they reproduced the word resolved in letters to parents.

Here is what verification actually requires, in order, before the June 22 deadline forces a decision:

  1. Reconcile the two scopes against the same storage system. One Medical’s confirmed incident is a third-party file store of legacy Iora Health records. The first question is whether ShinyHunters’ claimed haul is that same environment described at its true size, a separate access path the company has not disclosed, or an exaggeration. Those are three very different incidents wearing one headline.
  2. Demand a sample, on your terms, through counsel. The only thing that converts an extortion claim from noise to fact is data. If ShinyHunters wants to be believed, it has to prove possession. A controlled request for proof-of-life records, run through incident-response counsel and not through the company’s communications team, is how you find out whether 8.8 terabytes is real without conceding anything.
  3. Pull the logs on the third-party store, not just One Medical’s own systems. The confirmed vector is a vendor-hosted environment. The access logs that matter are the vendor’s. “No other One Medical or Amazon systems were affected” can be entirely true and still miss the size of what left the vendor.
  4. Date the exposure honestly. One Medical dates access to June 8 through 11 and discovery to June 13. If the real dwell time is longer, the regulatory clock and the breadth of exfiltration both change. The first reported window is almost never the final one.
$3.9B
What Amazon paid for One Medical in 2023, one of the largest tech-into-healthcare acquisitions on record.
8.8 TB vs. "a subset"
ShinyHunters' claimed haul versus One Medical's confirmed scope. No sample data has been released to substantiate the larger figure.
2021
The year One Medical acquired Iora Health, whose archived records sat in the breached third-party storage system.

The reckoning here is regulatory before it is reputational, because this is healthcare.

One Medical is a HIPAA covered entity. Protected health information carried a breach-notification regime long before extortion groups industrialized this. If the confirmed storage incident involves demographic and clinical records of senior patients, the HIPAA Breach Notification Rule obligations attach to the number One Medical can verify, not the number ShinyHunters claims. But if the 8.8-terabyte figure turns out to be real, the notification population, the state attorney-general exposure, and the Office for Civil Rights interest all scale with it. The dangerous move for a covered entity is to notify against the small number, have the large number prove out later, and then explain to a regulator why the first notification understated the event. Regulators remember which way an organization rounded.

There is a structural lesson underneath the specific incident, and it is the most useful thing a board can take from this. The vector here is a legacy, third-party file storage system holding records from an acquired company. That is not an edge case. It is one of the most common blind spots in healthcare security and in post-acquisition technology estates generally. Iora Health was acquired in 2021. The records outlived the integration. Somebody kept them in a vendor-hosted archive, and the archive kept its access open long enough for a criminal group to walk through it. Every organization that has bought another organization is holding some version of that archive right now.

The questions a board should be asking this week are not about One Medical. They are about your own estate:

  • Where do we hold records inherited from companies we acquired, and who has access to that storage today?
  • For every third-party system that holds our regulated data, do we get the vendor’s access logs, or do we get the vendor’s assurances?
  • When a threat actor claims a number larger than our confirmed scope, who in this organization is authorized to demand proof, and who is authorized to decide we were wrong?
  • If we had to notify against the larger number tomorrow, could we, or would we be reconstructing a patient list from a vendor we no longer actively manage?

Cloudskope advises boards on exactly this scenario: the moment when a company’s confirmed scope and an extortion group’s claimed scope diverge, the deadline is days away, and the decision has to be made on incomplete evidence. The instinct in that moment is to anchor on the smaller, friendlier number, because it is the one that comes from your own people. That instinct is the trap. The smaller number is a starting hypothesis. It is not a finding until the logs prove it.

Related Reading

Sources

Conclusion

One Medical's deadline is tomorrow, and the only outcome worse than a threat actor inflating a number is a covered entity that believed its own smallest estimate right up until the data landed.

CLOUDSKOPE VIEW

TAGS