{"id":620635,"date":"2026-09-10T18:38:12","date_gmt":"2026-09-10T18:38:12","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/620635\/"},"modified":"2026-09-10T18:38:12","modified_gmt":"2026-09-10T18:38:12","slug":"shinyhunters-expose-6-4m-in-attack-on-medical-supplier-mckesson","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/620635\/","title":{"rendered":"ShinyHunters expose 6.4M in attack on medical supplier McKesson"},"content":{"rendered":"<p class=\"kicker above\" style=\"\">\n        Security\n    <\/p>\n<p class=\"subtitle below\" style=\"\">\n        Have I Been Pwned logs leaked records spanning patients, staff, and providers\n    <\/p>\n<p>McKesson&#8217;s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP).<\/p>\n<p>The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time.<\/p>\n<p>ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP did not confirm that figure.<\/p>\n<p>The cybercriminals<a href=\"https:\/\/www.theregister.com\/cyber-crime\/2026\/08\/31\/healthcare-cyberattacks-hit-pacemakers-and-millions-of-patient-records\/5293537\" target=\"_blank\" class=\"italic m-italic \" rel=\"nofollow noopener\"> told The Register<\/a> that they issued a $55.2 million extortion demand to prevent the release of McKesson&#8217;s data \u2013 a sum that apparently was not paid, given the subsequent publication of the data.<\/p>\n<p>HIBP said: &#8220;The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff, and healthcare provider contacts.&#8221;<\/p>\n<p>The types of information exposed vary between individuals, but the records collectively include names, email and physical addresses, genders, dates of birth, phone numbers, employer details, and sensitive health information.<\/p>\n<p>This is broadly consistent with ShinyHunters&#8217; claims that the stolen data included appointment dates and notes, as well as sensitive medical details such as the locations of patients&#8217; cancers.<\/p>\n<p>ShinyHunters also claimed to have stolen Social Security numbers (SSNs) as part of the breach, but HIBP did not include these in its analysis of the leaked corpus.<\/p>\n<p>The Register asked McKesson to comment on <a href=\"https:\/\/haveibeenpwned.com\/Breach\/McKesson\" target=\"_blank\" rel=\"nofollow noopener\">HIBP&#8217;s assessment<\/a>.<\/p>\n<p>The company, which supports 3,300 oncology providers in 29 states, has not publicly confirmed the scale of the breach or issued further details since the <a href=\"https:\/\/www.mckesson.com\/utility\/cybersecurity\/customer-cybersecurity-information-center\/\" target=\"_blank\" rel=\"nofollow noopener\">last update<\/a> from its CIO and CTO on August 29.<\/p>\n<p>Medical device maker Boston Scientific disclosed a cyberattack at around the same time as McKesson, but has suffered a different kind of fallout.<\/p>\n<p>While McKesson is informing the millions of individuals affected by its breach, Boston Scientific told shareholders that disruption from its attack means it expects to<a href=\"https:\/\/www.theregister.com\/security\/2026\/09\/08\/boston-scientific-left-nursing-its-bottom-line-after-cyberattack\/5295026\" target=\"_blank\" rel=\"nofollow noopener\"> miss its sales and earnings guidance for Q3<\/a>.<\/p>\n<p>An <a href=\"https:\/\/news.bostonscientific.com\/update-on-recent-cybersecurity-incident\" target=\"_blank\" rel=\"nofollow noopener\">update<\/a> issued on Wednesday said manufacturing, order fulfillment, and shipping operations had been fully restored, although work to restore some business applications continued.<\/p>\n<p>Healthtech company Veradigm also <a href=\"https:\/\/www.sec.gov\/Archives\/edgar\/data\/1124804\/000119312526385249\/mdrx-20260908.htm\" target=\"_blank\" rel=\"nofollow noopener\">disclosed a cyberattack<\/a> to US regulators this week, days after ransomware group The Gentlemen claimed responsibility.<\/p>\n<p>Veradigm said attackers obtained credentials from a third-party vendor&#8217;s environment and used them to access a company API, stealing patient data without disrupting operations.<\/p>\n<p>The Gentlemen claimed to have stolen around 3.5 million records containing personally identifiable information (PII), including SSNs. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"Security Have I Been Pwned logs leaked records spanning patients, staff, and providers McKesson&#8217;s cyberattack last month affected&hellip;\n","protected":false},"author":2,"featured_media":620636,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[34],"tags":[103,397,396,61,60],"class_list":["post-620635","post","type-post","status-publish","format-standard","has-post-thumbnail","category-healthcare","tag-health","tag-health-care","tag-healthcare","tag-ie","tag-ireland"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/620635","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=620635"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/620635\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/620636"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=620635"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=620635"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=620635"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}