← Latest briefing

Technology

Hackers claim millions of patient records stolen in McKesson breach

Pharmaceutical distribution giant McKesson confirmed hackers breached cloud-hosted accounts, leading to service disruptions and compromised customer data.

The short version

  • The ShinyHunters hacking group claimed responsibility for breaching pharmaceutical distributor McKesson and stealing millions of patient and employee records.
  • McKesson confirmed that intruders accessed several cloud-hosted accounts, causing intermittent service degradation across its oncology, multispecialty, and medical-surgical units.
  • The stolen data reportedly includes names, Social Security numbers, addresses, diagnoses, medications, and patient notes.
  • The hackers have reportedly demanded a $55 million ransom to prevent the public release of the exfiltrated files.

Key facts

  • McKesson confirmed hackers breached several cloud-hosted accounts and exfiltrated data, causing expected intermittent service degradation.[TechCrunch]
  • The ShinyHunters hacking group claimed it used phishing and social engineering to access McKesson's network.[TechCrunch]
  • McKesson CTO Francisco Fraga stated in a customer notice that affected data pertains to the company's oncology & multispecialty and medical-surgical units.[TechCrunch]
  • Bleeping Computer reported that the perpetrators demanded a $55 million ransom to withhold the release of the stolen files.[TechCrunch]

What remains uncertain

  • The total number of individual patients and employees affected remains unverified.[TechCrunch]
  • McKesson did not comment on the reported $55 million ransom demand.[TechCrunch]

Sources