6.4 million records leaked in McKesson pharmaceutical breach
Have I Been Pwned (HIBP) has confirmed that a cyberattack on medical and pharmaceutical supply company McKesson last month affected roughly 6.4 million individuals, giving the first clear indication of the breach's scale. The data was leaked by the extortion group ShinyHunters, who had initially claimed to have stolen 284 million documents and demanded $55.2 million (£43 million) from McKesson to prevent publication, a sum that apparently went unpaid before the records were released.
The leaked records cover a wide range of people, including patients, staff, marketing recipients and healthcare provider contacts, with exposed information varying by individual but collectively including names, addresses, genders, dates of birth, phone numbers, employer details and sensitive health data such as appointment notes and cancer locations. HIBP did not include Social Security numbers in its analysis despite ShinyHunters' claims that these were also stolen, and McKesson, which supports 3,300 oncology providers across 29 US states, has not publicly confirmed the figures since its last update on 29 August. The breach comes amid a wave of healthcare-sector attacks, with Boston Scientific warning it will miss Q3 financial guidance due to a separate incident, and Veradigm disclosing a breach in which attackers used stolen third-party credentials to access patient data via a company API.
- ShinyHunters leak confirmed to affect 6.4 million McKesson-linked individuals
- $55.2 million extortion demand apparently went unpaid before data release
- Boston Scientific and Veradigm also hit by separate recent healthcare breaches
New here? Start with this
Off-the-shelf pharmacy chains, hospitals and GP surgeries across the United States rely on McKesson, one of the largest medical and pharmaceutical distribution companies, to supply medicines and support services such as cancer treatment programmes. Last month the company was hit by a cyberattack, and a criminal group known as ShinyHunters, which specialises in stealing and leaking data for extortion, obtained a large amount of internal information before demanding a payment to prevent its release.
The payment was apparently not made, and the stolen data has since been published. It affects millions of people connected to McKesson in different ways, including patients, employees and healthcare providers, and includes personal details and, in some cases, sensitive medical information.
This matters because McKesson plays a significant role in supplying and supporting healthcare services in the US, and breaches of this kind raise concerns about how safe personal and medical data is when held by large companies in the sector. It also comes at a time when several other healthcare and medical technology firms have reported similar cyber incidents, prompting wider questions about security across the industry.
Read the full article at the source →
Originally published by The Register as “ShinyHunters expose 6.4M in attack on medical supplier McKesson”.