All NewsEducationTVBrokers
Equities & FundsCrypto & Digital AssetsAI & TechnologyBusiness & CorporateUS Politics & PolicyGeopolitics & Global RiskMacro, Rates & FXCommodities & EnergyEuropean Politics & MarketsAsia-PacificReal Estate & Property
All NewsHome
← Back to AI & Technology

Hackers claim millions of patient records stolen from McKesson

Created at 31 Aug · 6:21 PM1 source↑ Market-relevant
IN SHORT

The hacking group ShinyHunters claims to have stolen millions of patient records from healthcare giant McKesson. The group used phishing and social engineering tactics to gain access to the company's cloud environments, exfiltrating sensitive personal and health information.

Key Numbers

$55 millionransom demanded by hackers

Who's Involved

McKesson
U.S. pharmaceutical distributor targeted in cyberattack
ShinyHunters
Hacking group claiming responsibility for the breach
Francisco Fraga
McKesson Chief Technology Officer
Hackers claim millions of patient records stolen from McKesson

↳ Why This Matters

This data breach at McKesson highlights the ongoing vulnerability of the healthcare sector to sophisticated cyberattacks, potentially exposing millions of individuals to identity theft and medical fraud. It underscores the critical need for robust cybersecurity measures within healthcare organizations that handle vast amounts of sensitive patient data.

Key facts

  • The hacking group ShinyHunters claims responsibility for a cyberattack on McKesson.
  • Millions of patient records, including personal and health information, were allegedly stolen.
  • The breach occurred through compromised cloud-hosted accounts, likely via phishing and social engineering.
  • McKesson confirmed the data exfiltration and expected service degradation.
  • The stolen data includes patient diagnoses, medications, and notes, as well as employee information.
  • The hackers are reportedly demanding a $55 million ransom.

The hacking group ShinyHunters has claimed responsibility for a significant cyberattack against McKesson, a major U.S. pharmaceutical distributor. The group alleges that it exfiltrated millions of patient records, including sensitive personal and health information, by exploiting employee credentials through phishing and social engineering tactics. McKesson confirmed the breach, stating that hackers accessed several cloud-hosted accounts and that the company anticipates intermittent service disruptions.

The stolen data reportedly includes names, addresses, Social Security numbers, diagnoses, medications, and patient notes. Information belonging to McKesson employees was also compromised. ShinyHunters, known for its data extortion activities, has demanded a $55 million ransom in exchange for not releasing the stolen files. This incident marks the latest in a series of cyberattacks targeting healthcare companies, which hackers increasingly see as lucrative targets due to the sensitive nature of the data they hold.

Frequently asked questions

The stolen data reportedly includes personal information such as names, addresses, and Social Security numbers, as well as protected health information like diagnoses, medications, and patient notes. Employee information was also compromised.

The ShinyHunters group claims to have used phishing and social engineering tactics to trick McKesson employees into granting them access to the company's cloud environment.

ShinyHunters is described as a prolific and active data-extortion hacking group known for carrying out large-scale data breaches.

McKesson confirmed the cyberattack and data exfiltration, stating that they expect intermittent service degradation related to the incident. They have not commented on the ransom demand.

What Happens Next

01McKesson is expected to provide further updates on the incident.
02The company may face regulatory investigations and potential fines.
03The stolen data may be leaked or sold on the dark web.

How It Developed

Hackers claimed to have breached McKesson's cloud environment.
McKesson confirmed a cyberattack occurred, leading to data exfiltration.
The stolen data includes patient names, addresses, Social Security numbers, diagnoses, and medications.
McKesson employees' information was also compromised.
The hacking group ShinyHunters is known for data extortion tactics.
ShinyHunters demanded a $55 million ransom for the stolen data.
McKesson is the latest in a series of healthcare companies targeted by cyberattacks.

Sources

T1
Hackers claim millions of patient records stolen during data breach at healthcare giant McKessonTechCrunch

Related Stories

Australian police arrest two men accused of widespread open-source software hacking
31 Aug · 4:11 PM
Media streaming devices pose security risks via proxy networks
31 Aug · 4:41 PM
AI cyber risk top global financial stability concern, watchdog warns
31 Aug · 6:04 AM
NTT Data and Palo Alto Networks Forge Global AI Cybersecurity Alliance
31 Aug · 3:26 PM
Microsoft tests fix for hours-long Outlook outage
31 Aug · 7:21 PM