Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Data Breaches

McKesson Confirms Data Breach as Attacker Deadline Looms

The ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems.

Medical and healthcare cybersecurity

Healthcare giant McKesson Corporation over the weekend confirmed that hackers exfiltrated customer data from its systems, as the ShinyHunters extortion group is threatening to release the stolen information.

McKesson delivers roughly one-third of prescription medicines to North American hospitals, pharmacies, and healthcare clinics. It also provides medical supplies, supports cancer treatment and specialty care, and operates the Health Mart pharmacy franchise.

In a filing with the US Securities and Exchange Commission, the healthcare and pharma giant said it discovered “a cybersecurity incident affecting its information systems” on August 25.

In a Friday notice on its website, the company said the incident involved third-party applications and data theft, but noted that it was not disconnecting any systems in response.

On Saturday, McKesson confirmed that the hackers had exfiltrated data associated with “a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units”.

The company said that the unauthorized access to its systems had been disrupted, and underlined that its services were not affected by the incident, and that complimentary credit monitoring and identity protection services would be provided to the impacted individuals.

Advertisement. Scroll to continue reading.

However, the healthcare giant did not share details on the type of data that was exfiltrated, the number of affected people, or who was behind the attack.

McKesson’s disclosure came around the same time that the notorious extortion group ShinyHunters added the company to its Tor-based leak site.

Responsible for multiple high-profile data breaches over the past couple of years, ShinyHunters is known to demand ransom payments in exchange for deleting data exfiltrated from its victims.

In McKesson’s case, the hacking group is threatening to make the stolen information public unless the company contacts them to start payment negotiations by September 1.

ShinyHunters reportedly boasted about stealing 284 million customer records from McKesson and about demanding approximately $55 million from the company.

The compromised information allegedly includes personally identifiable information (PII), protected health information (PHI), medical and treatment information, prescription and billing records, employee records, and information about McKesson’s customer physicians and clinics.

Responding to a SecurityWeek inquiry, a McKesson spokesperson provided the following statement:

“McKesson continues to operate in all lines of business. Our services, solutions, and network capabilities remain operational and continue to serve biopharma companies, healthcare providers, pharmacies, manufacturers, governments, and others. We continue to accept orders and ship products throughout our distribution network.

Customers can continue to connect to and use our systems and services as intended.

Upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to support our response.

Based on our investigation to date, we have confirmed the activity was associated with subsets of our Oncology & Multispecialty and Medical-Surgical business units. We have reasonable assurance of no ongoing unauthorized activity in our systems and continue to monitor our environment closely.

Our investigation remains ongoing, and we continue to fully ascertain the scope of information that may have been accessed or acquired. Any updates about the nature and scope of this incident will come from our team at McKesson and be posted on McKesson.com/cybersecurity.”

*Updated with statement from McKesson.

Related: Boston Scientific Still Recovering From Cyberattack

Related: Extortion Group Claims Manchester Airports Group Data Breach

Related: Berlin Won’t Pay Extortion Group Claiming Data Theft

Related: Hasbro Data Breach Exposed Employee Personal Information

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.