{"id":756612,"date":"2026-09-01T11:46:16","date_gmt":"2026-09-01T11:46:16","guid":{"rendered":"https:\/\/www.newsbeep.com\/uk\/756612\/"},"modified":"2026-09-01T11:46:16","modified_gmt":"2026-09-01T11:46:16","slug":"healthcare-cyberattacks-hit-pacemakers-and-millions-of-patient-records","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/uk\/756612\/","title":{"rendered":"Healthcare cyberattacks hit pacemakers and millions of patient records"},"content":{"rendered":"<p class=\"kicker \" style=\"\">Security<\/p>\n<p class=\"subtitle \" style=\"\">McKesson admits breach as ShinyHunters demands $55.2M<\/p>\n<p>Two major healthcare businesses, Boston Scientific and McKesson, disclosed more details over the weekend about separate cyberattacks that disrupted global operations and resulted in stolen patient data, respectively.<\/p>\n<p>Medical-device maker Boston Scientific, whose IT systems were <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/26\/boston-scientific-discloses-global-disruption-in-ongoing-cyberattack\/5292641\" rel=\"nofollow noopener\" target=\"_blank\">hacked by unknown intruders last week<\/a>, said the cyberattack remains ongoing. It also noted that pacemakers and other heart devices implanted after the August 25 breach cannot provide remote monitoring and data transmission as intended.<\/p>\n<p>\u201cNew remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated,\u201d the medtech firm <a href=\"https:\/\/news.bostonscientific.com\/update-on-recent-cybersecurity-incident\" rel=\"nofollow noopener\" target=\"_blank\">said<\/a> in a late Friday update.\u00a0<\/p>\n<p>This applies to all new cardiac rhythm management implants other than insertable cardiac monitors (ICM).\u00a0<\/p>\n<p>ICM devices must be activated using the Boston Scientific Clinic Assistant app to ensure the device correctly records patients\u2019 heart rhythms, the company added.\u00a0<\/p>\n<p>Because of the cyberattack, \u201cnew ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app,\u201d according to the update.\u00a0<\/p>\n<p>The devices will still record any episodes, and patients can transmit these to the remote monitoring system by in-person transmission via the Clinic Assistant app. This is done by selecting the \u201cinterrogate\u201d button, according to the company.<\/p>\n<p>Once its IT systems are back up and running, and the heart devices can pair with home monitoring equipment, they will again transmit recorded data to the remote systems.<\/p>\n<p>However, the company does not have a timeline for full restoration. \u201cWe are currently working on restoring affected functions and systems access,\u201d Boston Scientific said on Saturday.<\/p>\n<p>The digital intrusion also affected the firm\u2019s manufacturing, shipping, and ordering, it noted. \u201cWe are expeditiously working towards partial restoration for the shipping of some products this week,\u201d according to a Sunday update. \u201cOnce we can demonstrate the restoration is fully operable, we anticipate ordering and shipping will ramp up to full capacity.\u201d<\/p>\n<p>Boston Scientific has hired CrowdStrike to assist with the investigation and restoration efforts, and said the attack did not affect its cloud-based systems and apps &#8211; just \u201ccertain on-premise systems\u201d &#8211; and added that it has seen no indication of unauthorized IT activity since August 25.<\/p>\n<p>The firm has repeatedly declined to answer The Register\u2019s questions about the compromise, including whether it was a ransomware infection and which criminal crew is responsible.<\/p>\n<p>McKesson confirms breach as ShinyHunters claims responsibility<\/p>\n<p>Meanwhile, in another cybersecurity incident that has been very publicly claimed by the criminal perpetrator: pharmaceutical and medical supply giant McKesson over the weekend confirmed an intrusion after ShinyHunters on Friday told The Register it broke into the company\u2019s Snowflake and Salesforce instances and stole millions of patients\u2019 data.<\/p>\n<p>\u201cBased on our investigation thus far, including assessments by leading cybersecurity industry experts supporting our response, we\u2019ve confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology &amp; Multispecialty and Medical-Surgical business units,\u201d Francisco Fraga, McKesson executive VP, chief information officer and chief technology officer, said in a Saturday statement.\u00a0<\/p>\n<p>The medical firm did not immediately respond to The Register\u2019s questions, including how many patients were affected and what \u201ccertain data\u201d was stolen. McKesson supports about 3,300 oncology providers in 29 states, according to its website.\u00a0<\/p>\n<p>Fraga\u2019s statement noted that distribution centers remain operational and McKesson continues to ship products. The firm has \u201creasonable assurance\u201d that the digital intruders have been kicked out of the third-party environments and aren\u2019t lurking around McKesson\u2019s systems, he added.<\/p>\n<p>A ShinyHunters spokesperson told us that the notorious extortion group compromised more than 284 million records of patient data, and demanded McKesson pay $55.2 million or else they would leak the stolen data.<\/p>\n<p>However, as Have I Been Pwned boss Troy Hunt recently <a href=\"https:\/\/www.theregister.com\/security\/2026\/08\/26\/carhartt-data-breach-affects-129m-half-of-what-shinyhunters-claimed\/5292626\" rel=\"nofollow noopener\" target=\"_blank\">reminded<\/a> everyone: Don\u2019t confuse criminals\u2019 claims with gospel truth, and \u201ctake headline numbers with a grain of salt unless you&#8217;re confident in the processes of those making the claims.&#8221;\u00a0<\/p>\n<p>This was after Hunt\u2019s HIBP service reported 12.9 million individuals affected by retailer Carhartt\u2019s alleged breach. This number was around half of what ShinyHunters claimed when they leaked the company\u2019s data earlier this month.<\/p>\n<p>The McKesson records, according to the ShinyHunters spokesperson, include patients\u2019 full names, home and email addresses, phone numbers, dates of birth, Social Security numbers, appointment dates and notes, and sensitive illness details including cancer locations on people\u2019s bodies. The group also claims to have swiped emails containing private information from doctors to patients.<\/p>\n<p>The spokesperson told us they accessed the company\u2019s Snowflake and Salesforce instances by voice phishing \u201cmultiple employees.\u201d This is a <a href=\"https:\/\/www.theregister.com\/security\/2026\/03\/09\/shinyhunters-claims-yet-another-salesforce-customers-breach\/5220118\" rel=\"nofollow noopener\" target=\"_blank\">tried-and-true method<\/a> <a href=\"https:\/\/www.theregister.com\/special-features\/2026\/03\/23\/voice-phishing-skyrockets-as-smooth-crims-talk-their-way-in\/5223759\" rel=\"nofollow noopener\" target=\"_blank\">popularized<\/a> by the data-theft-and-extortion gang, which has victimized other medical providers in recent months. These include\u00a0<a href=\"https:\/\/www.theregister.com\/security\/2026\/07\/02\/pacemaker-manufacturer-medtronic-warns-patients-cybercrooks-may-have-swiped-health-data\/5265768\" rel=\"nofollow noopener\" target=\"_blank\">pacemaker manufacturer Medtronic<\/a> in April, and\u00a0<a href=\"https:\/\/www.theregister.com\/cyber-crime\/2026\/08\/07\/shinyhunters-called-cancer-diagnostics-biz-and-tricked-staffers-into-giving-them-access-now-theyve-dumped-109m-email-addresses\/5284857\" rel=\"nofollow noopener\" target=\"_blank\">cancer diagnostics business Exact Sciences<\/a> in July. \u00ae<\/p>\n","protected":false},"excerpt":{"rendered":"Security McKesson admits breach as ShinyHunters demands $55.2M Two major healthcare businesses, Boston Scientific and McKesson, disclosed more&hellip;\n","protected":false},"author":2,"featured_media":756613,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[43],"tags":[102,2960,56,54,55],"class_list":["post-756612","post","type-post","status-publish","format-standard","has-post-thumbnail","category-healthcare","tag-health","tag-healthcare","tag-uk","tag-united-kingdom","tag-unitedkingdom"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/756612","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/comments?post=756612"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/posts\/756612\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media\/756613"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/media?parent=756612"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/categories?post=756612"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/uk\/wp-json\/wp\/v2\/tags?post=756612"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}