Ethical Hacking News
ShinyHunters' cyber heist has exposed the sensitive information of 6.4 million individuals, sparking concerns about the safety and security of the healthcare sector. The breach, which was first reported in August, has left medical professionals and patients reeling, and raises serious questions about the effectiveness of cybersecurity measures in place at McKesson.
Approximately 6.4 million individuals' sensitive information was compromised in the breach of medical supplier McKesson. The stolen records include names, email addresses, physical addresses, genders, dates of birth, phone numbers, employer details, and sensitive health information. McKesson has not publicly confirmed the scale of the breach, although it has informed the millions of individuals affected. The breach highlights the vulnerability of medical suppliers to cyberattacks and the need for greater vigilance and cooperation among suppliers, regulators, and law enforcement agencies. The healthcare sector must take a proactive approach to cybersecurity, investing in robust measures to protect patient data and prevent future breaches.
In a shocking revelation, the cybercrime group known as ShinyHunters has exposed a massive breach of medical supplier McKesson, compromising the sensitive information of approximately 6.4 million individuals. The breach, which was first reported in August, has left medical professionals and patients reeling, as the group made an initial extortion demand of $55.2 million to prevent the release of the stolen data. However, it appears that the ransom was not paid, and the data has now been leaked by the group.
According to data analysis by the breach notification service Have I Been Pwned (HIBP), the stolen records include names, email addresses, physical addresses, genders, dates of birth, phone numbers, employer details, and sensitive health information, including appointment dates and notes, as well as medical details such as the locations of patients' cancers. Notably, ShinyHunters claimed to have stolen Social Security numbers (SSNs) as part of the breach, although HIBP did not include these in its analysis of the leaked corpus.
The breach is particularly concerning, given the sensitive nature of the information involved. McKesson, which supports 3,300 oncology providers in 29 states, has not publicly confirmed the scale of the breach or issued further details since an initial update from its CIO and CTO on August 29. The company has since informed the millions of individuals affected by the breach, although it is unclear what steps will be taken to mitigate the damage.
In a wider context, the breach highlights the vulnerability of medical suppliers to cyberattacks. Boston Scientific, another medical device manufacturer, disclosed a cyberattack at around the same time as McKesson, and has since suffered a significant impact on its sales and earnings guidance for Q3. Veradigm, a healthtech company, also disclosed a cyberattack to US regulators this week, days after ransomware group The Gentlemen claimed responsibility.
The breach also raises questions about the effectiveness of cybersecurity measures in place at McKesson. While the company has not publicly confirmed the scale of the breach, it has acknowledged that an attack occurred, and has taken steps to restore manufacturing, order fulfillment, and shipping operations. However, the extent to which these measures have mitigated the damage remains unclear.
In addition to the breach at McKesson, there have been several other high-profile cyberattacks on medical suppliers and healthcare organizations in recent weeks. Trezor and BitBox users were targeted in a phishing spree, while German optics giant ditches greenfield SAP migration. These incidents highlight the growing threat of cyberattacks to the healthcare sector, and the need for greater vigilance and cooperation among suppliers, regulators, and law enforcement agencies.
As the investigation into the breach at McKesson continues, it is clear that the consequences of this attack will be felt for some time to come. The exposure of sensitive patient records and the potential for further cyberattacks raise serious concerns about the safety and security of the healthcare sector. It is essential that the relevant authorities, including regulatory bodies and law enforcement agencies, take swift and decisive action to address this crisis and ensure that the necessary measures are taken to prevent future breaches.
In the short term, McKesson has taken steps to restore its operations, although the extent to which these measures have mitigated the damage remains unclear. The company has also informed the millions of individuals affected by the breach, although it is unclear what support will be provided to those affected. In the longer term, the healthcare sector must take a proactive approach to cybersecurity, investing in robust measures to protect patient data and prevent future breaches.
The breach at McKesson serves as a stark reminder of the vulnerability of medical suppliers to cyberattacks, and the need for greater vigilance and cooperation among suppliers, regulators, and law enforcement agencies. As the healthcare sector continues to navigate the increasingly complex landscape of cybersecurity threats, it is essential that the necessary measures are taken to protect patient data and prevent future breaches.
Related Information:
https://www.ethicalhackingnews.com/articles/ShinyHunters-Cyber-Heist-Unpacking-the-64-Million-Patient-Records-Breached-by-McKesson-ehn.shtml
https://www.theregister.com/security/2026/09/10/shinyhunters-expose-64m-in-attack-on-medical-supplier-mckesson/5295550
Published: Thu Sep 10 10:04:50 2026 by llama3.2 3B Q4_K_M