The hacking group ShinyHunters has claimed responsibility for the cyberattack that struck McKesson, the Texas-based pharmaceutical distribution giant, last week. The group told TechCrunch that it breached McKesson鈥檚 cloud environment by tricking several employees into granting access through phishing and social engineering tactics. McKesson confirmed on Friday that hackers broke into several of its cloud-hosted accounts and exfiltrated data, and the company warned of intermittent service degradation related to the incident. The stolen data affects patients tied to the company鈥檚 oncology and multispecialty and medical-surgical units, as detailed in a notice from Chief Technology Officer Francisco Fraga.
ShinyHunters, one of the most active data-extortion crews of the past two years, said it stole a range of personal information, including names, addresses, and Social Security numbers. The hackers also claimed to have taken protected health information such as diagnoses, medications, allergies, and patient notes. They said the data came from McKesson鈥檚 cloud-hosted Snowflake and Salesforce environments and that they took millions of rows of patient data, though they are unsure how many individuals are ultimately affected. The stolen files also included employee information, such as home addresses. TechCrunch verified a small subset of the data against public records after reviewing screenshots and samples from the group.
Bleeping Computer, which first reported the link to ShinyHunters, said the hackers demanded a $55 million ransom from McKesson in exchange for not publicly releasing the stolen files. A McKesson spokesperson did not respond to TechCrunch鈥檚 request for comment on Monday. McKesson is one of the largest American distributors of pharmaceuticals, medicines, medical supplies, and technology to hospitals and healthcare providers across the United States, so the breach has a direct impact on a wide network of U.S. healthcare institutions and their patients.
The incident places McKesson among a string of healthcare companies and medical device makers targeted in recent months. Last week, Boston Scientific suffered a cyberattack that knocked much of its network offline. Earlier this year, Stryker faced a similar attack in which hackers abused internal tools to remotely wipe thousands of employee devices. Abbott Laboratories and Medtronic have also experienced cyberattacks, while electronic patient records provider CareCloud and health tech company TriZetto each had breaches affecting over three million patients.
ShinyHunters has also taken credit for sizable data breaches at Amazon-owned OneMedical and dental insurance company DentaQuest following cyberattacks on their systems. The repeated targeting of healthcare firms reflects a pattern where hackers aim to steal large amounts of sensitive medical and health data to extort companies into paying ransoms to prevent public release. The full scope of the McKesson breach remains unclear as the company continues to assess the damage, but the exposure of millions of data rows signals a significant U.S. consumer and patient privacy concern.
More cybersecurity news from TechManNews.








