McKesson has disclosed a cybersecurity incident involving unauthorised access to third-party applications and data theft. ShinyHunters claims it stole roughly 284 million patient-related data records.

McKesson data breach investigation remains ongoing

McKesson discovered the incident on August 25 and disclosed it in a filing with the US Securities and Exchange Commission.

The company said it activated its incident-response procedures, started an investigation and engaged external cybersecurity experts. It has not identified the affected third-party applications or disclosed the types of data involved.

McKesson also said it has not determined that the incident is material or likely to have a material impact on its financial condition or operations.

However, customers may experience intermittent service degradation while the company investigates. McKesson said it is not proactively disconnecting systems from its environment.

ShinyHunters claims access through vishing attacks

The ShinyHunters extortion group claimed responsibility for the McKesson data breach.

According to the group, attackers used voice-phishing attacks to target several employees. They allegedly impersonated the company’s help desk and IT teams through a domain matching McKesson’s name.

ShinyHunters claims the campaign compromised multiple Okta single sign-on accounts. It says the stolen access then allowed attackers to reach McKesson’s Salesforce and Snowflake environments.

McKesson has not confirmed these claims.

Group claims theft of 284 million data records

ShinyHunters said it exfiltrated around 1TB of data between August 21 and August 25.

The group initially claimed it stole data connected to 284 million patients. However, it later clarified that this number refers to approximately 284 million data records, rather than 284 million unique people.

The group claims the data includes names, addresses, dates of birth, Social Security numbers, patient and medical-record identifiers, contact details and health information.

It also alleges that the stolen material includes prescription and shipment details, invoices, employee records, internal communications and information about healthcare providers.

These claims have not been independently verified, and McKesson has not publicly confirmed what information attackers took.

Attackers reportedly demanded $55 million

ShinyHunters said it contacted McKesson after the alleged theft and demanded a $55,236,150 ransom.

The group claimed it gave the company 72 hours to respond. It also alleged that McKesson did not negotiate over the demand.

The reported incident follows a broader wave of ShinyHunters attacks targeting healthcare and health-technology organisations. These campaigns commonly rely on social engineering to gain access to corporate accounts and cloud platforms.

The McKesson data breach remains under investigation. Customers, partners and healthcare providers should remain alert for suspicious messages that impersonate the company or request sensitive information.


0 responses to “McKesson Discloses Cyberattack as ShinyHunters Claims Patient Data Theft”