Hackers Claim Massive Theft of Patient Data in Breach at Healthcare Giant McKesson
Hackers claim they stole millions of patient records from McKesson, a major U.S. healthcare distributor, in a cyberattack last week.
McKesson confirmed Friday that hackers had broken into several of its cloud-hosted accounts and exfiltrated data, warning of "intermittent service degradation" related to the incident. In a notice to customers, the company's chief technology officer, Francisco Fraga, said the stolen data relates to its oncology and multispecialty and medical-surgical units.
The ShinyHunters hacking group, one of the most active data-extortion crews of the past two years, told TechCrunch that it gained access by tricking several McKesson employees with phishing and social engineering techniques. The hackers said they stole personal information including names, addresses and Social Security numbers, as well as protected health information such as diagnoses, medications, allergies and patient notes. They said they took millions of rows of patient data from McKesson's cloud-hosted Snowflake and Salesforce environments, though they were unsure how many individuals are ultimately affected. The stolen data also included employee information, such as home addresses.
ShinyHunters shared screenshots and a sample of the stolen data with TechCrunch, which verified a small subset against public records. Bleeping Computer, which first reported the link to the hacking group, said the hackers demanded a $55 million ransom from McKesson in exchange for not publicly releasing the stolen files. A spokesperson for McKesson did not respond to TechCrunch's request for comment.
McKesson, based in Texas, is one of the largest U.S. distributors of pharmaceuticals, medicines, medical supplies and technology to hospitals and healthcare providers, handling large volumes of patient data. The company is the latest healthcare firm or medical device maker to be targeted in a wave of cyberattacks in recent months as hackers seek massive amounts of sensitive medical data to extort payments. Last week, medical device maker Boston Scientific was hit by a cyberattack that knocked much of its network offline. Similar attacks have hit Stryker, Abbott Laboratories, Medtronic, CareCloud and TriZetto, with breaches affecting millions of patients. ShinyHunters has also taken credit for data breaches at Amazon-owned OneMedical and dental insurance company DentaQuest.