Healthcare industry leader McKesson Corporation has recently acknowledged a significant cybersecurity breach, with the ShinyHunters extortion group threatening to disclose sensitive customer data. The company, a major supplier of prescription medications and medical supplies in North America, confirmed the breach over the weekend.
Details of the Cybersecurity Incident
McKesson, which also supports cancer treatment and specialty care, reported the incident to the US Securities and Exchange Commission on August 25. The company revealed that unauthorized access to its systems had been detected, and specifically mentioned third-party applications and data theft. Despite the breach, McKesson decided not to disconnect its systems, emphasizing that its services remain operational.
On Saturday, McKesson clarified that the data exfiltration affected a specific group of customers within its Oncology & Multispecialty and Medical-Surgical divisions. The company has assured that the breach has been contained and has promised to offer credit monitoring and identity protection services to those impacted.
Extent and Impact of the Data Breach
While McKesson has not disclosed the type of data stolen, the number of individuals affected, or the identity of the attackers, the ShinyHunters group has taken responsibility. Known for high-profile data breaches, ShinyHunters has listed McKesson on its Tor-based leak platform, demanding a ransom to prevent the release of the stolen information.
The extortionists claim to have accessed 284 million customer records and are reportedly demanding $55 million from McKesson. The compromised data allegedly includes personally identifiable information (PII), protected health information (PHI), medical and treatment details, prescription and billing records, as well as employee and customer physician information.
Ongoing Threats and Industry Response
ShinyHunters has set a deadline of September 1 for McKesson to initiate ransom negotiations. The group is notorious for demanding payments in exchange for deleting exfiltrated data from its victims. SecurityWeek has reached out to McKesson for further comments on the hackers’ claims but has not yet received a response.
This incident underscores the ongoing challenges faced by major corporations in safeguarding sensitive data against cyber threats. As similar breaches continue to occur across various industries, organizations are urged to implement robust security measures to protect their systems and customer information.
This situation is part of a broader trend of cyberattacks targeting prominent companies, such as those recently faced by Boston Scientific, Manchester Airports Group, and Hasbro, reminding the industry of the importance of constant vigilance and enhanced security protocols.
