Ransomware Group ShinyHunters Claims Attack on Sharecare, Inc.

A ransomware group calling itself ShinyHunters claims to have carried out an attack on Sharecare, Inc., with the claim dated August 13, 2026. This claim comes from the group’s own leak-site listing, which has been tracked by ransomware.live, a security research platform that monitors ransomware groups’ public leak sites. At this time, the claim is unverified — Sharecare has not confirmed any incident, and no regulator has issued a statement regarding this matter.

What we know — and don’t
  • A group identifying itself as ShinyHunters listed Sharecare, Inc. on its leak site with a claimed date of August 13, 2026.
  • Sharecare operates in the digital health and wellness space, placing this claim within the broader healthcare sector.
  • The specific data types the group alleges to have obtained have not been disclosed or confirmed by any party.
  • Sharecare, Inc. has not issued a public statement confirming or denying the claim as of this writing.
  • No regulatory filing or independent verification of the claim has surfaced at this time.
What should you do if you have an account with this company?
  • Change your password for your Sharecare account and any other accounts where you may have reused the same credentials.
  • Enable two-factor authentication (2FA) wherever it is offered, including on your email and other linked accounts.
  • Be cautious of unexpected emails, texts, or calls referencing Sharecare or health-related services, as these could be phishing attempts exploiting this claim.
  • Avoid clicking on links or downloading attachments from unsolicited messages claiming to be from Sharecare or related healthcare providers.
  • Consider signing up for identity monitoring, such as a service like Aura or LifeLock, to help detect potential misuse of your personal information going forward.
  • Keep an eye on account statements and health records for any unfamiliar activity.

BreachLetter will update this page if Sharecare, Inc. confirms the incident or if it is officially reported to regulators.

Leave a Comment