McKesson, a medical and pharmaceutical supply company supporting 3,300 oncology providers across 29 states, has not publicly confirmed the scale of the breach since its CIO and CTO last updated stakeholders on August 29. The HIBP analysis, which added the leaked data to its database, revealed that the impacted records include marketing campaign recipients, patients, staff, and healthcare provider contacts.
The types of exposed information vary between individuals but collectively include names, email and physical addresses, genders, dates of birth, phone numbers, employer details, and sensitive health information. ShinyHunters claimed the stolen data also contained Social Security numbers and detailed medical notes such as the locations of patients' cancers, though HIBP did not include SSNs in its assessment.
ShinyHunters told The Register that they issued a $55.2 million extortion demand to prevent the release of McKesson's data. The subsequent publication of the data suggests the demand was not met. McKesson has not responded to requests for comment on HIBP's findings.
The breach comes amid a spate of healthcare cyberattacks. Medical device maker Boston Scientific disclosed a separate incident that has disrupted its operations, leading the company to warn shareholders it expects to miss Q3 sales and earnings guidance. Healthtech firm Veradigm also reported a cyberattack to US regulators this week, after ransomware group The Gentlemen claimed responsibility for stealing 3.5 million records containing personally identifiable information, including Social Security numbers.