US healthcare giant McKesson has confirmed a cybersecurity incident involving unauthorized access to third-party applications and data theft, while the ShinyHunters extortion group claims it obtained approximately 284 million records from the company.
McKesson discovered the incident on August 25th and disclosed it in a Form 8-K filed with the US Securities and Exchange Commission. The company said its investigation remains at an early stage and that it has not determined the attack to be material or likely to materially affect its financial condition or operating results.
In information provided to customers, McKesson confirmed that data was exfiltrated after unauthorized access to third-party applications. It has not identified the affected applications publicly or explained how access was obtained.
McKesson activated its incident response procedures after discovering the breach and brought in external cybersecurity specialists to assist with the investigation. Based on the information currently available, the company said customers do not need to take action and that it is not actively disconnecting systems.
ShinyHunters has separately claimed responsibility and provided significantly more extensive allegations about the intrusion. According to the group, the 284 million figure represents an approximate number of records rather than 284 million unique patients.
The attackers claim the stolen information includes names, addresses, Social Security numbers, medical records, diagnoses, prescription information, and billing data. ShinyHunters also alleges that particularly sensitive information involving terminal illnesses, causes of death, and sexual orientation appears in the stolen material.
Data belonging to employees, physicians, and clinics, along with communications between doctors and patients, was also allegedly obtained. McKesson has not confirmed these specific claims.
ShinyHunters claims it gained initial access by targeting multiple McKesson employees with voice phishing. The group alleges that compromised employee Okta accounts subsequently provided access to the company’s Salesforce and Snowflake environments.
According to the attackers, approximately one terabyte of information was exfiltrated over four days between August 21st and August 25th. ShinyHunters also claims it gained extensive access to McKesson’s Salesforce environment, including support cases. These details remain claims from the threat actor and have not been independently confirmed by McKesson.
The group says it demanded $55,236,150 from McKesson and gave the company 72 hours to respond. ShinyHunters claims McKesson did not reply or enter negotiations.
McKesson is one of the largest US distributors of prescription drugs and medical supplies and also provides healthcare technology services. The company has not yet disclosed how many individuals were affected by the incident or confirmed whether the categories of patient information described by ShinyHunters were stolen.