The ShinyHunters hacking group has provided TechCrunch with screenshots and a sample of data stolen from McKesson, which TechCrunch verified a small subset of against public records. The hackers claim to have stolen names, addresses, Social Security numbers, and protected health information including diagnoses, medications, allergies, and patient notes from the company's cloud-hosted Snowflake and Salesforce environments. They said they are unsure how many individuals are ultimately affected.
BleepingComputer reported that ShinyHunters demanded a $55 million ransom from the company in exchange for not publicly releasing the stolen files. McKesson spokesperson Kristina Chang said the company “continues to operate in all lines of business,” reiterated its public statement, and noted that McKesson believes it has no ongoing unauthorized activity in its systems. The company would not answer questions about the ransom demand or the number of affected individuals.
In a separate notice to customers, McKesson’s chief technology officer, Francisco Fraga, said the stolen data relates to its oncology & multispecialty and medical-surgical units.
McKesson first disclosed the incident on August 25 in a Form 8-K filing with the SEC, stating the investigation is in early stages and that it had not determined the incident to be material. The company said it immediately activated incident response protocols and engaged cybersecurity experts.
The ShinyHunters group told BleepingComputer it gained access through voice phishing (vishing) social engineering attacks against multiple McKesson employees, using the domain mckesson[.]claims as part of the campaign. McKesson warned customers that intermittent service degradation may occur, though it is not proactively disconnecting systems.
McKesson is the latest in a string of cyberattacks targeting healthcare companies, following recent incidents at Boston Scientific and Stryker.