Were you recently affected by a data breach?

Sharecare Data Breach

Reports have emerged that hacker group ShinyHunters claims to have breached Sharecare, a digital health company behind AskMD, allegedly exposing millions of Salesforce records containing personal information for patients, providers, and partners.

Sharecare
Date of Breach: Reported August 14, 2026 (incident allegedly occurred on or about August 13, 2026)
CAU logo

Who was affected:

Clients of Sharecare

Impacted Data:

Personal information allegedly contained in Sharecare’s Salesforce customer relationship management records; specific data types have not yet been publicly confirmed

Sharecare, Inc., a digital health company based in Atlanta, Georgia that provides health engagement tools and services to patients, providers, employers, and insurers, is facing reports of a possible data breach. As a company that manages personal and health-related information as part of its platform, Sharecare has a responsibility to keep that data secure, and any confirmed lapse could leave affected individuals vulnerable to fraud and identity theft.

Sharecare’s Data Breach Investigation

According to dark web monitoring sites Ransomware.live and DeXpose, the hacker group known as ShinyHunters claimed responsibility for an attack on Sharecare, alleging that the intrusion resulted in the exposure of more than 3.4 million Salesforce records containing personally identifiable information. The claim, posted on or around August 14, 2026, states that the underlying incident occurred approximately one day earlier, on or about August 13, 2026. As of this writing, Sharecare has not issued a public confirmation of the incident, and the scope and nature of any actual data exposure remain unverified.

Reports of this nature typically begin with a claim posted by a hacker group on a dark web leak site or forum, well before the affected company has completed its own investigation or issued a formal notification. This pattern has played out repeatedly in 2026, as ShinyHunters and affiliated groups have been linked to a wave of attacks targeting companies’ Salesforce customer relationship management environments across a range of industries, from insurance to healthcare to retail. In many of these cases, the attackers are alleged to gain initial access through compromised third-party integrations or credentials connected to a company’s Salesforce instance, rather than through a direct breach of the company’s own core systems.

Because Sharecare operates as a digital health platform connecting patients, providers, employers, and insurers, any confirmed exposure of records tied to its Salesforce environment could potentially include a mix of contact information, account details, and other data submitted through the company’s various services. Health-adjacent companies are frequent targets for this kind of attack precisely because the data they store, even data used for customer relationship management rather than direct clinical records, can carry significant value to cybercriminals and can be used to craft convincing phishing attempts referencing a person’s real interactions with a healthcare-related company.

It is important to note that, as of publication, the claims described here originate from the hacker group itself and from third-party dark web monitoring platforms, not from a confirmed statement by Sharecare. Companies facing this kind of allegation often take time to investigate before issuing a public response, and the ultimate scope of any confirmed breach can turn out to be smaller, larger, or different in nature than an attacker’s initial claim. Individuals who are current or former Sharecare employees, patients, or partners should nonetheless remain alert for updates and should not wait for a formal notification letter before taking basic precautions.

When Did This Breach Occur?

According to the ShinyHunters claim reported by dark web monitoring platforms, the underlying incident is alleged to have occurred on or about August 13, 2026, with the claim itself surfacing publicly on August 14, 2026. Sharecare had not issued its own public timeline or confirmation of these dates as of this writing.

What Information Was Breached?

ShinyHunters has alleged that the incident resulted in the exposure of more than 3.4 million Salesforce records containing personally identifiable information, but the specific data fields involved, such as names, contact details, or other information, have not yet been publicly confirmed by Sharecare or independently verified. Individuals concerned about their information should watch for an official statement or notification from the company, which would typically specify the exact categories of data involved.

What You Can Do

If you are a current or former Sharecare patient, employee, or partner and are concerned about this reported incident, consider taking the following steps:

  • Watch for an official communication from Sharecare confirming whether your information was involved and what data was affected.
  • Consider placing a fraud alert or credit freeze with Equifax, Experian, and TransUnion as a precaution, which is free and can help prevent new accounts from being opened in your name.
  • Monitor your financial accounts and any health-plan or insurance statements for unfamiliar activity.
  • Be cautious of unsolicited emails, texts, or calls referencing Sharecare or this reported breach, since scammers frequently use real breach news to run phishing schemes before all the facts are confirmed.
  • Consider speaking with an attorney about your legal options if you believe your information may have been affected.

File a Data Breach Lawsuit Against Sharecare

If your personal information was exposed in connection with the reported Sharecare data breach, you may be entitled to compensation, even if you have not yet experienced direct financial harm. Companies that manage personal and health-related data have a responsibility to protect it, and reports of an incident like this one raise real questions about whether adequate safeguards were in place.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: Not publicly disclosed
Date of Breach: Reported August 14, 2026 (incident allegedly occurred on or about August 13, 2026)
Date of Breach: Reported June 26, 2026
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.