Beta The Briev beta is out. Free on iPhone via TestFlight — install it in under a minute.

Join the beta ↗
Briev
Live
Health

ShinyHunters reveal breach affecting 6.4 million people at medical supplier McKesson

The breach notification service Have I Been Pwned confirmed that a cyberattack on McKesson exposed data on roughly 6.4 million individuals, as disclosed by the extortion group ShinyHunters.

Have I Been Pwned added a new breach entry showing that a recent cyberattack on medical distributor McKesson compromised data belonging to approximately 6.4 million individuals. The leak, first highlighted by the extortion group ShinyHunters, includes personal and professional details such as names, email and physical addresses, genders, dates of birth, phone numbers, employer information and certain health records. While ShinyHunters earlier asserted they stole 284 million documents, the breach service could only confirm the smaller figure and did not find Social Security numbers in the released corpus.

The criminals demanded $55.2 million to prevent publication of the data, a ransom that appears to have gone unpaid, leading to the data’s public exposure. McKesson, which supports 3,300 oncology providers across 29 states, has not issued a detailed statement beyond an earlier update from its CIO and CTO. The incident follows parallel cyber incidents at Boston Scientific, which warned of missed earnings guidance, and Veradigm, where the ransomware group The Gentlemen claimed to have taken 3.5 million patient records.

Why it matters

Millions of patients and healthcare workers may face identity theft and privacy risks from the disclosed medical data breach.

In this story

McKesson breach6.4 million recordsShinyHuntersextortion demandhealth data leakHave I Been PwnedBoston Scientific cyberattackVeradigm incident
Get the beta ↗