deniz.in

Markets

Weather

Loading weather

· via TechCrunch

ShinyHunters claim millions of patient records stolen in McKesson data breach

McKesson says intruders accessed cloud-hosted accounts and stole data tied to its oncology and medical-surgical units, while ShinyHunters claims millions of patient records and a $55 million ransom demand.

ShinyHunters claim millions of patient records stolen in McKesson data breach

Attack confirmed by McKesson

McKesson, one of the largest distributors of pharmaceuticals and medical supplies in the United States, has confirmed that hackers broke into several of its cloud-hosted accounts and exfiltrated data. According to TechCrunch, the company disclosed the incident in a statement on its website on Friday and warned that it expected intermittent disruption to its services as a result.

In a separate notice to customers, chief technology officer Francisco Fraga said the stolen data relates to the company's oncology and multispecialty unit as well as its medical-surgical business. McKesson, based in Texas, supplies hospitals and healthcare providers across the country and handles large volumes of patient information as part of that role.

How the breach happened

The ShinyHunters hacking group, described by TechCrunch as one of the most active data-extortion crews of the past two years, told the outlet that it carried out the attack. According to the group, it used phishing and social engineering to trick several McKesson employees into granting access to the corporate network, an approach the group is known for.

The hackers said they pulled data from McKesson's cloud-hosted Snowflake and Salesforce environments and took millions of rows of patient records, though they are unsure how many individuals are ultimately affected. TechCrunch reviewed screenshots and a sample of the stolen data provided by the group and verified a small subset of it against public records.

Bleeping Computer, which first linked ShinyHunters to the incident, reported that the group demanded a $55 million ransom from McKesson in exchange for not publicly releasing the stolen files. TechCrunch said a McKesson spokesperson had not responded to a request for comment as of Monday.

Sensitive data at stake

Based on the hackers' claims, the stolen haul includes personal information such as names, addresses and Social Security numbers, alongside protected health information including diagnoses, medications, allergies and patient notes. Home addresses of McKesson employees were also reportedly part of the taken data.

The true number of affected patients remains unconfirmed. Neither the hackers nor the company has put a precise figure on how many people's records were compromised, and McKesson's public statement did not detail the full scope of the incident.

Part of a wider wave of healthcare attacks

McKesson is the latest healthcare company to be hit in a string of recent cyberattacks. TechCrunch notes that medical device maker Boston Scientific suffered an attack last week that knocked much of its network offline, while an earlier incident at device maker Stryker saw hackers abuse internal tools to remotely wipe thousands of employee devices. Abbott Laboratories and Medtronic have also experienced cyberattacks, and breaches at electronic patient records provider CareCloud and health tech company TriZetto each affected more than 3 million patients.

ShinyHunters has additionally claimed credit for breaches at Amazon-owned primary care company One Medical and dental insurer DentaQuest.

Why it matters

The incident underlines how a handful of tricked employees can open the door to data at enormous scale, given that distributors like McKesson sit at the center of the U.S. healthcare supply chain and concentrate records from many providers in one place. Health records pair identity data such as Social Security numbers with clinical details that, unlike a password, can never be changed, making them valuable to extortionists and risky for patients long after an incident is contained.

The reported $55 million demand also illustrates the economics behind the current wave of attacks: crews increasingly skip encryption entirely, steal data and threaten publication instead. For patients, the practical fallout ranges from identity fraud to scams that exploit medical details, and the breach is another signal that phishing-resistant authentication on cloud accounts has become a core requirement for healthcare security rather than an optional hardening step.

  • #data-breach
  • #cybersecurity
  • #healthcare
  • #cloud-security
  • #phishing

Related posts