Ethical Hacking News
Millions of patient records have been compromised in a series of sophisticated cyberattacks on pacemakers and healthcare providers. Boston Scientific and McKesson have disclosed separate breaches, with the latter being attributed to the notorious extortion group ShinyHunters. The breaches highlight the growing threat of cyberattacks in the healthcare sector and the need for robust cybersecurity measures to protect sensitive patient information.
Two major healthcare businesses, Boston Scientific and McKesson, have been targeted by separate cyberattacks resulting in the compromise of millions of patient records.Boston Scientific's pacemaker business was significantly impacted, with pacemakers and other heart devices not providing remote monitoring and data transmission as intended.McKesson's breach resulted in the compromise of sensitive patient information, including full names, home and email addresses, phone numbers, and Social Security numbers.The cyberattacks highlight the growing threat of sophisticated cyberattacks in the healthcare sector and the need for robust cybersecurity measures.The breaches also raise concerns about the effectiveness of cybersecurity measures and the need for increased vigilance, particularly against social engineering attacks.Healthcare providers are advised to take proactive steps to protect their systems and data, including implementing robust cybersecurity measures and educating employees about cybersecurity best practices.
In recent days, two major healthcare businesses, Boston Scientific and McKesson, have disclosed separate cyberattacks that have resulted in the compromise of millions of patient records. The attacks, which are believed to have occurred in August and July, respectively, highlight the growing threat of sophisticated cyberattacks in the healthcare sector.
According to reports, Boston Scientific, a medical-device manufacturer, was the target of an ongoing cyberattack that began on August 25. The company's IT systems were hacked by unknown intruders, who gained access to certain on-premise systems. The attackers were able to disrupt global operations, including manufacturing, shipping, and ordering, and also affected the company's manufacturing, shipping, and ordering processes.
The attack had a significant impact on Boston Scientific's pacemaker business, with the company stating that pacemakers and other heart devices implanted after the breach could not provide remote monitoring and data transmission as intended. However, the company has hired CrowdStrike to assist with the investigation and restoration efforts, and said the attack did not affect its cloud-based systems and apps.
Meanwhile, McKesson, a pharmaceutical and medical supply giant, confirmed an intrusion after ShinyHunters, a notorious extortion group, told The Register that it had broken into the company's Snowflake and Salesforce instances and stolen millions of patients' data. The attack resulted in the compromise of sensitive patient information, including full names, home and email addresses, phone numbers, dates of birth, Social Security numbers, appointment dates, and notes, as well as emails containing private information from doctors to patients.
The ShinyHunters group, which has a history of compromising medical providers, claimed that it had accessed the company's Snowflake and Salesforce instances by voice phishing "multiple employees." This is a tried-and-true method popularized by the group, which has victimized other medical providers in recent months.
The McKesson breach has significant implications for the company and its customers. McKesson supports about 3,300 oncology providers in 29 states, and the breach may have affected a large number of patients. The company has stated that distribution centers remain operational, but it is unclear how long it will take to fully restore its systems and services.
The cyberattacks on Boston Scientific and McKesson are part of a growing trend of sophisticated cyberattacks in the healthcare sector. As healthcare providers increasingly rely on digital systems and networks, they are becoming more vulnerable to cyber threats. The breaches highlight the need for robust cybersecurity measures and the importance of protecting sensitive patient information.
The attacks also raise questions about the effectiveness of cybersecurity measures and the need for increased vigilance. ShinyHunters' claims that it accessed McKesson's systems by voice phishing "multiple employees" raise concerns about the potential for social engineering attacks. The group's demand for $55.2 million in exchange for not leaking the stolen data is also a concerning development.
In light of these breaches, it is essential for healthcare providers to take proactive steps to protect their systems and data. This may include implementing robust cybersecurity measures, conducting regular security audits, and educating employees about cybersecurity best practices.
The cyberattacks on Boston Scientific and McKesson serve as a wake-up call for the healthcare sector, highlighting the need for increased vigilance and robust cybersecurity measures. As the threat landscape continues to evolve, it is essential for healthcare providers to stay ahead of the curve and take proactive steps to protect their systems and data.
Related Information:
https://www.ethicalhackingnews.com/articles/Millions-of-Patient-Records-Compromised-in-Sophisticated-Cyberattacks-on-Pacemakers-and-Healthcare-Providers-ehn.shtml
https://www.theregister.com/cyber-crime/2026/08/31/healthcare-cyberattacks-hit-pacemakers-and-millions-of-patient-records/5293537
Published: Mon Aug 31 17:54:39 2026 by llama3.2 3B Q4_K_M