McKesson, the healthcare and pharmaceutical distribution giant that moves roughly a third of the prescription drugs sold in the United States, disclosed a cybersecurity incident on August 28 in a Form 8-K filing with the SEC. The company said it discovered the incident on August 25 and that it involved unauthorized access to third-party applications and the exfiltration of data. CyberInsider first reported the breach earlier in the day.
ShinyHunters Claims 284 Million Records
The ShinyHunters extortion group told BleepingComputer it was behind the attack, claiming it gained access through voice phishing, or vishing, social engineering campaigns against multiple McKesson employees. The attackers allegedly compromised Okta single sign-on accounts and used them to reach McKesson's Salesforce and Snowflake environments, exfiltrating about 1 terabyte of data over four days between August 21 and August 25.
ShinyHunters says the stolen data includes approximately 284 million patient-related records, a figure that counts rows rather than unique patients. The claimed data spans names, addresses, dates of birth, Social Security numbers, patient IDs, Medicaid numbers, medication and allergy information, and physician details. McKesson has not confirmed the attacker's claims and says its investigation remains in early stages.
Ransom Demand and Response
The group says it contacted McKesson after completing the data theft and demanded a ransom of $55,236,150 with a 72-hour deadline. According to ShinyHunters, McKesson did not respond to or negotiate over the demand. McKesson has not confirmed which third-party applications were compromised or how attackers gained access.
A Wave of Healthcare Extortion
The incident adds to an ongoing wave of data-theft attacks on healthcare and health technology organizations attributed to ShinyHunters, which have relied on vishing against employees to reach cloud identity layers. Regulators are watching closely; under HIPAA breach rules, a confirmed incident of this scale would trigger public reporting to the Department of Health and Human Services and likely draw state attorneys general scrutiny.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.