Healthcare giant McKesson Corporation over the weekend confirmed that hackers exfiltrated customer data from its systems, as the ShinyHunters extortion group is threatening to release the stolen information.
McKesson delivers roughly one-third of prescription medicines to North American hospitals, pharmacies, and healthcare clinics. It also provides medical supplies, supports cancer treatment and specialty care, and operates the Health Mart pharmacy franchise.
In a filing with the US Securities and Exchange Commission, the healthcare and pharma giant said it discovered “a cybersecurity incident affecting its information systems” on August 25.
In a Friday notice on its website, the company said the incident involved third-party applications and data theft, but noted that it was not disconnecting any systems in response.
On Saturday, McKesson confirmed that the hackers had exfiltrated data associated with “a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units”.
The company said that the unauthorized access to its systems had been disrupted, and underlined that its services were not affected by the incident, and that complimentary credit monitoring and identity protection services would be provided to the impacted individuals.
However, the healthcare giant did not share details on the type of data that was exfiltrated, the number of affected people, or who was behind the attack.
McKesson’s disclosure came around the same time that the notorious extortion group ShinyHunters added the company to its Tor-based leak site.
Responsible for multiple high-profile data breaches over the past couple of years, ShinyHunters is known to demand ransom payments in exchange for deleting data exfiltrated from its victims.
In McKesson’s case, the hacking group is threatening to make the stolen information public unless the company contacts them to start payment negotiations by September 1.
ShinyHunters reportedly boasted about stealing 284 million customer records from McKesson and about demanding approximately $55 million from the company.
The compromised information allegedly includes personally identifiable information (PII), protected health information (PHI), medical and treatment information, prescription and billing records, employee records, and information about McKesson’s customer physicians and clinics.
SecurityWeek has contacted McKesson for a statement on the hackers’ claims and will update this article if the company responds.
Related: Boston Scientific Still Recovering From Cyberattack
Related: Extortion Group Claims Manchester Airports Group Data Breach
Related: Berlin Won’t Pay Extortion Group Claiming Data Theft
Related: Hasbro Data Breach Exposed Employee Personal Information
