Hackers Reportedly Compromise Millions of Patient Records in Data Breach at Healthcare Giant McKesson
A notorious hacking group has taken credit for the recent cyberattack on McKesson, a prominent pharmaceutical distribution company in the U.S., representing yet another significant breach of sensitive health data from an American healthcare organization in recent months.
On Friday, McKesson released a statement on its website acknowledging that hackers accessed multiple cloud-based accounts earlier that week and extracted data. The company noted that it expects “intermittent service degradation” related to the incident. In a separate update to customers, the firm’s chief technology officer, Francisco Fraga, mentioned that the compromised information relates to its oncology & multispecialty and medical-surgical divisions.
Headquartered in Texas, McKesson ranks as one of the top distributors of pharmaceuticals, medical supplies, and technology to healthcare providers throughout the United States, managing a vast range of patient information.
The hacking group ShinyHunters—deemed one of the most active data-extortion teams in the past two years—told TechCrunch that they compromised McKesson’s cloud infrastructure by tricking several employees into granting access via phishing and social engineering tactics, which they are well-known for.
As claimed by the hackers, they obtained a variety of personal information, including names, addresses, and Social Security numbers, as well as protected health information such as diagnoses, medications, allergies, and patient notes. They assert that they extracted millions of rows of patient data from McKesson’s cloud-hosted Snowflake and Salesforce platforms, though they are unsure of the total number of affected individuals.
Moreover, the stolen data also included personal information about McKesson employees, such as their home addresses.
ShinyHunters has provided screenshots and samples of the stolen data to TechCrunch, with a small portion being verified against public records.
Bleeping Computer, which was the first to link the incident to the ShinyHunters group, reported that the hackers demanded a ransom of $55 million from McKesson to prevent public disclosure of the stolen data.
In response, McKesson spokesperson Kristina Chang stated that the company “continues to operate in all lines of business,” affirming the company’s public statement and asserting that it believes there is no ongoing unauthorized activity within its systems. The company did not respond to TechCrunch’s questions about the incident, including the hackers’ demands or the number of individuals affected.
McKesson is the latest healthcare provider or medical device manufacturer to face a cyberattack, as hackers aim to steal large quantities of sensitive medical and health data to extort companies for ransom to prevent its release.
Last week, Boston Scientific, a medical device manufacturer, encountered a cyberattack that disrupted much of its network. This incident mirrored an earlier attack this year on Stryker, another medical device maker, where hackers utilized internal tools to remotely wipe thousands of employee devices. Other companies like Abbott Laboratories and Medtronic have also experienced cyber incidents, in addition to breaches affecting over 3 million patients each at electronic patient records provider CareCloud and health tech company TriZetto.
The ShinyHunters group has also claimed responsibility for significant data breaches at Amazon-owned One Medical and dental insurance provider DentaQuest after their systems were targeted.
Lorenzo Franceschi-Bicchierai contributed reporting. Updated with comments from a McKesson spokesperson.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


