Healthcare cyberattacks hit pacemakers and millions of patient records
Medical-device maker Boston Scientific and pharmaceutical distributor McKesson both disclosed weekend updates on separate cyberattacks affecting their US healthcare operations, one disrupting pacemaker monitoring and shipping, the other exposing millions of patient records. The incidents highlight the growing vulnerability of healthcare infrastructure to cybercrime, with attacks now reaching beyond data theft into physical medical devices and disrupting care delivery, manufacturing and distribution networks relied upon by hospitals and cancer clinics.
Boston Scientific said the breach, first detected on 25 August, remains unresolved: newly implanted pacemakers and other cardiac devices cannot transmit data remotely until systems are restored, though episodes are still recorded and can be uploaded manually via an app. The firm has hired CrowdStrike, says cloud systems were unaffected, and is gradually restoring shipping, but has declined to confirm whether ransomware was involved. Separately, McKesson confirmed hackers accessed its Snowflake and Salesforce platforms, stealing data from patients in its Oncology & Multispecialty and Medical-Surgical units, which serve roughly 3,300 oncology providers across 29 states; the extortion group ShinyHunters claimed responsibility and reportedly demanded $55.2 million, though McKesson has not disclosed how many patients were affected.
- Boston Scientific breach disrupts pacemaker remote monitoring since 25 August
- McKesson confirms patient data theft from oncology and surgical units
- ShinyHunters claims McKesson hack, demands $55.2 million ransom