ShinyHunters steal millions of patient records from McKesson

The ShinyHunters hacking group has breached McKesson, stealing millions of patient records and demanding a $55 million ransom.

By Central
ShinyHunters exploited phishing and social engineering to access McKesson's cloud systems and exfiltrate sensitive health data.
Highlights
  • ShinyHunters gained access to McKesson's network by tricking employees through phishing and social engineering tactics.
  • The stolen data includes millions of patient records with names, Social Security numbers, diagnoses, and medications.
  • McKesson confirmed the breach and expects intermittent service degradation, but did not disclose the ransom demand.

The ShinyHunters hacking group has claimed responsibility for a major cyberattack against McKesson, one of the largest pharmaceutical distributors in the United States, exposing millions of patient records and sensitive health data. The breach, which unfolded over the past week, represents the latest in a growing wave of targeted attacks on healthcare companies that store vast troves of protected health information, and it underscores the acute vulnerability of cloud-based systems used across the industry.

How ShinyHunters Breached McKesson’s Cloud Environment

The hacking group, which has been one of the most active data-extortion crews since 2022, gained access to McKesson’s network by tricking several employees through phishing and social engineering tactics. According to the group’s direct communications, they exploited human error rather than technical vulnerabilities, a method that has become a hallmark of their operations. By convincing employees to grant access credentials, the hackers infiltrated McKesson’s cloud-hosted accounts, including those running on Snowflake and Salesforce platforms.

McKesson confirmed the breach on Friday via a statement on its website, noting that hackers broke into multiple cloud-hosted accounts earlier in the week and exfiltrated data. The company expected “intermittent service degradation” related to the incident. In a separate notice to customers, Francisco Fraga, McKesson’s chief technology officer, specified that the stolen data relates to the company’s oncology and multispecialty division, as well as its medical-surgical unit.

What Data Was Stolen in the McKesson Cyberattack

The ShinyHunters group claimed to have stolen millions of rows of patient data from McKesson’s Snowflake and Salesforce environments. The stolen information includes a broad range of personal identifiers and protected health information: names, addresses, Social Security numbers, diagnoses, medications, allergies, and patient notes. The hackers also took employee data, including home addresses. While they stated they are unsure how many individuals are ultimately affected, the scale of the data exfiltration is substantial given McKesson’s role as a distributor to hospitals and healthcare providers nationwide.

TechCrunch verified a small subset of the stolen data against public records, confirming its authenticity. The hackers also shared screenshots of the stolen data. Bleeping Computer reported that the group demanded a $55 million ransom from McKesson in exchange for not publicly releasing the files.

McKesson’s Response and Ongoing Operations

McKesson spokesperson Kristina Chang stated that the company “continues to operate in all lines of business” and reiterated that the company believes there is no ongoing unauthorized activity in its systems. However, McKesson declined to answer specific questions about the incident, including the nature of the ransom demand or the number of individuals affected. The company’s public statement focused on operational continuity and the expectation of temporary service degradation, but did not offer a timeline for full recovery or a detailed explanation of how the breach occurred.

The lack of transparency from McKesson, while not uncommon in the immediate aftermath of a cyberattack, raises concerns among healthcare providers and patients who rely on the company for pharmaceuticals and medical supplies. The stolen data includes Social Security numbers and protected health information, which can be used for identity theft, medical fraud, and targeted phishing campaigns.

The Broader Healthcare Cybersecurity Crisis

McKesson is the latest in a string of healthcare companies and medical device manufacturers to suffer major cyberattacks in recent months. Hackers are increasingly targeting the healthcare sector because of the high value of medical data on the black market and the critical nature of operations, which makes companies more likely to pay ransoms to avoid disruptions.

Last week, medical device maker Boston Scientific was hit by a cyberattack that knocked much of the company’s network offline, causing global disruption. Earlier this year, Stryker, another medical device maker, experienced an attack in which hackers abused internal tools to remotely wipe thousands of employee devices. Abbott Laboratories and Medtronic have also reported cyberattacks. Electronic patient records provider CareCloud confirmed that 3.7 million patients had their medical records stolen in a data breach, and health tech company TriZetto confirmed that 3.4 million people’s health and personal data was stolen during a separate breach.

This pattern reveals a systemic vulnerability in the healthcare industry’s reliance on cloud-based data storage and third-party platforms. Many healthcare organizations have migrated patient records and operational data to cloud environments like Snowflake and Salesforce, which offer scalability and analytics but also introduce new attack surfaces. The ShinyHunters group specifically targeted these environments, suggesting that the hackers have developed expertise in exploiting cloud misconfigurations, weak authentication, and social engineering.

ShinyHunters: A Prolific and Dangerous Threat

The ShinyHunters group has taken credit for several large-scale data breaches in the healthcare sector, including attacks on Amazon-owned One Medical and dental insurance company DentaQuest. The group is known for its aggressive use of extortion, typically demanding ransoms in the millions of dollars and threatening to leak stolen data publicly if demands are not met. Their modus operandi often involves initial access through phishing and social engineering, followed by lateral movement within victims’ networks and exfiltration of sensitive data.

The $55 million ransom demand against McKesson is among the highest reported in recent healthcare breaches, reflecting the group’s confidence in the value of the stolen data. It also signals that healthcare organizations may face increasingly steep financial demands as attackers recognize the criticality of their operations and the sensitivity of patient information.

What Does This Mean for Patient Privacy and Healthcare Security?

The McKesson breach illustrates the direct consequences of inadequate cybersecurity measures in the healthcare supply chain. When a pharmaceutical distributor handling data for thousands of hospitals and clinics is compromised, the ripple effects extend far beyond the company itself. Patients whose data was stolen may face years of vigilance against identity theft, and healthcare providers may need to invest in additional security measures to protect their own systems from follow-on attacks leveraging the stolen information.

Regulatory implications are also significant. McKesson is subject to the Health Insurance Portability and Accountability Act (HIPAA) and could face substantial fines and penalties if investigators determine that the company failed to implement adequate safeguards. The breach also raises questions about the security of cloud-based platforms like Snowflake and Salesforce, which are widely used in healthcare but may not be designed with the same level of security controls as purpose-built health information systems.

How Healthcare Organizations Can Protect Against Similar Attacks

Preventing attacks like the one on McKesson requires a multi-layered approach that addresses both technical and human vulnerabilities. Social engineering remains the most common entry point for groups like ShinyHunters, so employee training and phishing simulations are essential. However, technical controls such as multi-factor authentication, least-privilege access policies, and continuous monitoring of cloud environments can also reduce the risk of unauthorized access.

Organizations using cloud platforms like Snowflake and Salesforce should conduct regular security audits, enable logging and alerting for suspicious activity, and ensure that data is encrypted both at rest and in transit. The healthcare sector as a whole may need to reconsider its reliance on third-party cloud providers and demand stronger contractual security guarantees, including breach notification timelines and data residency requirements.

The Future of Healthcare Cybersecurity: A Call for Systemic Change

The McKesson breach is not an isolated incident but a symptom of a broader failure to secure the healthcare ecosystem. As more patient data moves to the cloud and as healthcare organizations integrate with supply chains, the attack surface expands. The ShinyHunters group has demonstrated that even large, well-resourced companies can be compromised through relatively simple social engineering tactics, and that the consequences can be devastating for millions of patients.

Regulators, including the Department of Health and Human Services and the Federal Trade Commission, are likely to intensify scrutiny of healthcare data security practices in the wake of this breach. Industry standards may evolve to require more rigorous third-party risk assessments, mandatory breach reporting within shorter timeframes, and stronger penalties for non-compliance. For patients, the breach serves as a reminder that personal health information is increasingly vulnerable, and that they should monitor their medical records and credit reports for signs of fraud.

The incident also highlights the need for a more coordinated response to ransomware and data extortion groups. Law enforcement agencies have had some success in disrupting ransomware operations, but groups like ShinyHunters continue to operate with impunity, often based in jurisdictions where extradition is difficult. International cooperation and information sharing between healthcare organizations and cybersecurity firms will be critical to reducing the frequency and impact of such attacks.

Ultimately, the McKesson breach is a stark warning that the healthcare industry must prioritize cybersecurity as a core business function, not an afterthought. The cost of prevention is far lower than the cost of a breach, both in financial terms and in the erosion of patient trust. As the investigation continues and more details emerge, the industry will be watching closely to see how McKesson responds and what lessons can be learned to prevent the next catastrophe.

Share This Article