Fresenius Medical Care confirmed September 22, 2026 that it found unauthorized access to a limited number of internal systems. The German dialysis and device maker said medical devices, patient care operations, and manufacturing were unaffected.
Hours earlier, the extortion group ShinyHunters listed Fresenius Medical Care as a victim. The posting gave the company two days to make contact, a deadline landing September 25, and threatened to publish data it described only as sensitive. It included no sample files, screenshots, or file listing, the evidence researchers usually look for before treating a claim as backed by a real intrusion.
Fresenius's own statement did not name ShinyHunters or confirm what the group claims to hold. The company said it contained the incident on discovery, engaged outside cybersecurity firms, notified law enforcement, and would meet its regulatory notification obligations as the investigation continues.
An extortion listing with no proof attached stays unverified until the forensics catch up. Fresenius's own admission of unauthorized system access already clears that bar on its own, separate from whatever ShinyHunters can or cannot back up.
ShinyHunters has run this playbook against device-adjacent manufacturers before, including the Salesforce-linked extortion attempt against Baxter in August. The pattern this year has favored back-office and cloud systems over the devices themselves, which is why Fresenius could confirm an intrusion and rule out medical devices in the same statement.