A prolific hacking group has claimed responsibility for a cyberattack that saw millions of patient records stolen from pharmaceutical giant McKesson. The breach, which affected the company’s cloud-hosted accounts, has led to the exposure of sensitive personal and health information. McKesson confirmed the breach, acknowledging potential service disruptions but maintaining it continues to operate.
The ShinyHunters group, known for its data extortion tactics, used phishing and social engineering to gain access to McKesson’s network. The stolen data includes names, addresses, Social Security numbers, diagnoses, medications, allergies, and patient notes. A spokesperson from McKesson declined to comment on the ransom demand or the number of affected individuals.
This latest incident comes amid a wave of cyberattacks targeting healthcare companies, as hackers seek to extort large amounts of sensitive data. Other recent victims include medical device maker Boston Scientific, and electronic patient records provider CareCloud. The ShinyHunters have also claimed responsibility for breaches at One Medical and DentaQuest.
The increasing frequency of such attacks highlights the ongoing challenges in securing patient data. As healthcare providers continue to digitize, the need for robust cybersecurity measures has never been more critical.







