McKesson discloses breach after ShinyHunters claims patient data theft
BLUF
McKesson confirmed a major breach involving 284 million patient records allegedly stolen by ShinyHunters via third-party app vulnerabilities.
NEWS
Healthcare distributor McKesson disclosed unauthorized access to third-party applications following claims by the ShinyHunters extortion group. The group asserts they exfiltrated 284 million patient data records, prompting an ongoing investigation into the scope of the compromise.
Why I Care
This breach exposes sensitive health information on a massive scale, increasing risks of identity theft and medical fraud for millions of patients while undermining trust in pharmaceutical distribution networks. Regulatory penalties under HIPAA and potential class-action lawsuits pose significant financial and reputational stakes for McKesson.
Next Steps
Affected individuals should monitor credit reports and enable multi-factor authentication immediately, while healthcare partners must audit their third-party vendor access controls within the next 30 days to prevent similar supply chain compromises.
Source: BleepingComputer ·