Desk live·
ForensicPost
Breaches/Healthcare/File 26-0613

ShinyHunters Claim 8.8TB From Amazon One Medical Legacy Archives

A claim against Amazon’s One Medical describes 8.8 terabytes taken from legacy patient archive systems over three days in June. The word doing the work in that sentence is “legacy”.

Constructed geometry · not a chart of case data
TargetAmazon One Medical
ActorShinyHunters
D. Kennedy9 min readConfidence: low1 source reviewed

A claim attributed to ShinyHunters describes 8.8 terabytes taken from legacy patient archive systems at Amazon’s One Medical between 8 and 11 June 2026. The volume figure originates with the group and we grade this file low accordingly.

The characterisation of the target is the durable part, and it does not depend on the volume being right.

Legacy Systems Fail Every Assumption

A legacy archive is one the organisation has stopped developing but not stopped holding. It typically predates the current identity infrastructure, runs software that cannot take current patches, is excluded from monitoring because its noise is unhelpful, and is owned by nobody.

It also holds the oldest and often most complete records, because it accumulated before anyone imposed retention discipline. Every property that makes it low priority makes it high value.

Acquisition Compounds It

One Medical was acquired. Acquisition reliably produces legacy estate: the buyer migrates the systems needed to operate and inherits the rest, frequently with incomplete documentation and staff who have moved on.

Diligence in these transactions concentrates on liabilities that appear on a balance sheet. A patient archive with no owner and no monitoring is a liability that appears nowhere until somebody copies it.

The claim would move to medium on confirmation of an incident, or to high on a stated affected population. Neither exists yet.

How we reported this

Compiled from public reporting, listed below. The volume figure and the target characterisation originate with the attacking group; we have not seen them corroborated by the company. We did not review any listed data. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary