Key facts
- The hacking group ShinyHunters claims responsibility for a cyberattack on McKesson.
- Millions of patient records, including personal and health information, were allegedly stolen.
- The breach occurred through compromised cloud-hosted accounts, likely via phishing and social engineering.
- McKesson confirmed the data exfiltration and expected service degradation.
- The stolen data includes patient diagnoses, medications, and notes, as well as employee information.
- The hackers are reportedly demanding a $55 million ransom.
The hacking group ShinyHunters has claimed responsibility for a significant cyberattack against McKesson, a major U.S. pharmaceutical distributor. The group alleges that it exfiltrated millions of patient records, including sensitive personal and health information, by exploiting employee credentials through phishing and social engineering tactics. McKesson confirmed the breach, stating that hackers accessed several cloud-hosted accounts and that the company anticipates intermittent service disruptions.
