The ShinyHunters hacking group told TechCrunch it hacked pharmaceutical distribution giant McKesson's cloud environment by tricking employees into granting access via phishing and social engineering, stealing names, addresses, Social Security numbers and protected health information including diagnoses, medications and patient notes - millions of rows from Snowflake and Salesforce environments. McKesson confirmed Friday that hackers broke into several cloud-hosted accounts and exfiltrated data, with the CTO saying the stolen data relates to oncology multispecialty and medical-surgical units.
McKesson is one of the largest US distributors of pharmaceuticals and medical supplies, handling vast volumes of patient data that underpin care across the country. The company expects intermittent service degradation related to the incident, and ShinyHunters has been one of the most active data-extortion crews of the past two years.
The breach is the latest spill of highly sensitive health data by an American healthcare company in recent months, heightening regulatory and legal exposure for McKesson. Stolen health records carry serious, lasting privacy and identity-fraud risks for millions of potential victims.

The ShinyHunters hacking group told TechCrunch it hacked pharmaceutical distribution giant McKesson's cloud environment by tricking employees into granting access via phishing and social engineering, stealing names, addresses, Social Security numbers and protected health information including diagnoses, medications and patient notes - millions of rows from Snowflake and Salesforce environments. McKesson confirmed Friday that hackers broke into several cloud-hosted accounts and exfiltrated data, with the CTO saying the stolen data relates to oncology multispecialty and medical-surgical units.

McKesson is one of the largest US distributors of pharmaceuticals and medical supplies, handling vast volumes of patient data that underpin care across the country. The company expects intermittent service degradation related to the incident, and ShinyHunters has been one of the most active data-extortion crews of the past two years.

The breach is the latest spill of highly sensitive health data by an American healthcare company in recent months, heightening regulatory and legal exposure for McKesson. Stolen health records carry serious, lasting privacy and identity-fraud risks for millions of potential victims.

πŸ“° Source: TechCrunch
techcrunch.com β†—
Was this article useful?