Hackers Claim Millions of Patient Records Stolen in Data Breach at Healthcare Giant McKesson

McKesson confirms data breach after ShinyHunters hacking group claims to steal patient records

A prolific hacking and extortion group has taken credit for a cyberattack against McKesson, one of the largest U.S. distributors of pharmaceuticals and medical supplies, in what’s now the latest in a string of major data breaches hitting American healthcare companies this year.

What McKesson Has Confirmed

McKesson confirmed in a statement on its website that hackers broke into several of its cloud-hosted accounts and exfiltrated data, and that the company expects “intermittent service degradation” related to the incident. In a separate notice to customers, chief technology officer Francisco Fraga said the stolen data relates to the company’s oncology & multispecialty and medical-surgical units.

McKesson spokesperson Kristina Chang told TechCrunch the company “continues to operate in all lines of business” and believes there is no ongoing unauthorized activity in its systems. McKesson declined to answer questions about what the hackers demanded or how many individuals had data affected.

Who’s Behind the Attack

The ShinyHunters hacking group, one of the most active data-extortion crews of the past two years, told TechCrunch it breached McKesson’s cloud environment by tricking employees into granting access through phishing and social engineering, tactics the group is well known for using. ShinyHunters said it stole data from McKesson’s cloud-hosted Snowflake and Salesforce environments, taking what it described as millions of rows of patient data, though the group said it’s unsure exactly how many individuals are affected.

According to the hackers, the stolen information includes names, addresses, and Social Security numbers, along with protected health information such as diagnoses, medications, allergies, and patient notes. McKesson employee data, including home addresses, was also reportedly taken. ShinyHunters shared screenshots and a data sample with TechCrunch, which verified a small subset against public records. Bleeping Computer, which first reported the link to ShinyHunters, said the group demanded a $55 million ransom in exchange for not publicly releasing the stolen files.

Part of a Longer Pattern in Healthcare

McKesson is the latest in a growing list of healthcare companies and medical device makers targeted by cyberattacks in recent months. Medical device maker Boston Scientific was hit by a cyberattack in late August that knocked much of its network offline. Earlier this year, pro-Iran hackers breached Stryker, abusing internal tools to remotely wipe thousands of employee devices. Abbott Laboratories and Medtronic have also experienced cyberattacks, while electronic patient records provider CareCloud confirmed 3.7 million patients had records stolen, and health tech company TriZetto confirmed a breach affecting 3.4 million people.

ShinyHunters specifically has also claimed credit for breaches at Amazon-owned One Medical and dental insurer DentaQuest, underscoring how frequently this particular group has targeted the healthcare sector specifically.

Why It Matters

Healthcare data breaches carry disproportionate risk compared to breaches in most other industries, because the stolen information, Social Security numbers combined with detailed medical histories, is both highly sensitive and extremely difficult for victims to change or protect after the fact, unlike a compromised password or credit card number. The recurring targeting of the same sector by the same well-documented extortion group also suggests healthcare companies’ cloud environments, and the employees with access to them, remain a persistent, exploitable weak point despite the sector’s repeated exposure this year.

What Affected Patients Should Do

Anyone who has received care through providers or facilities that rely on McKesson’s oncology, multispecialty, or medical-surgical distribution services should watch for a formal breach notification from McKesson or their healthcare provider, be alert to phishing attempts referencing medical information, and consider a credit freeze or fraud alert given the reported inclusion of Social Security numbers in the stolen data.

For continuing coverage of healthcare cybersecurity and major data breaches, keep following Tech News Reports for ongoing updates.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *