Particle.news

McKesson Faces Extortion Claim After Reported Theft of Patient Data

The incident puts sensitive patient and employee information at risk and pressures a company that handles a large share of U.S. drug distribution.

Overview

  • McKesson detected a cybersecurity incident on August 25 and says unauthorized access to third‑party cloud applications has been disrupted while services remain available and affected people will be offered credit monitoring.
  • The extortion group ShinyHunters says it used voice phishing to steal single‑sign‑on credentials, moved into Salesforce and Snowflake accounts, exfiltrated roughly 1 TB of data and is demanding about $55.2 million with a September 1 deadline, though those claims have not been independently verified.
  • The group asserts the haul includes names, Social Security numbers, medical and prescription records, billing and employee files, which could enable identity theft and convincing scam attempts against patients, staff and providers.
  • McKesson has filed disclosures with the SEC, engaged outside cybersecurity firms, and said its probe is in the early stages while it has not publicly confirmed the number of affected individuals or the specific data types taken.
  • Security researchers and authorities note this fits a rising pattern of ShinyHunters attacks that exploit social engineering and cloud identity weaknesses, and the episode could increase pressure on healthcare vendors to tighten third‑party and SSO security.