Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson

1 week ago 23

A prolific hacking radical has taken recognition for past week’s cyberattack against U.S. pharmaceutical organisation elephantine McKesson, starring to the latest spill of highly delicate wellness information by an American healthcare institution successful caller months.

McKesson confirmed Friday successful a connection connected its website that hackers broke into respective of its cloud-hosted accounts earlier successful the week and exfiltrated data, and that the institution expected “intermittent work degradation” related to the incident. In a abstracted announcement to customers, the company’s main exertion officer, Francisco Fraga, said the stolen information relates to its oncology & multispecialty and medical-surgical units.

The Texas-based institution is 1 of the largest American distributors of pharmaceuticals, medicines, aesculapian supplies, and exertion to hospitals and healthcare providers crossed the United States, and arsenic specified handles a ample magnitude of diligent data.

The ShinyHunters hacking radical — 1 of the astir progressive data-extortion crews of the past 2 years — told TechCrunch that it hacked the company’s unreality situation by tricking respective employees into granting the hackers’ entree to McKesson’s web by utilizing phishing and societal engineering tricks, which the radical is known for.

The hackers said they stole a scope of idiosyncratic information, specified arsenic names, addresses, and Social Security numbers, arsenic good arsenic protected wellness information, including diagnoses, medications, allergies, and diligent notes. The hackers accidental they took millions of rows of diligent information from the company’s cloud-hosted Snowflake and Salesforce environments, but that they are unsure of however galore individuals are yet affected.

The stolen information besides included McKesson employees’ information, specified arsenic location addresses.

ShinyHunters shared screenshots and a illustration of the stolen information with TechCrunch, and we verified a tiny subset of it against nationalist records.

Bleeping Computer, which archetypal reported the link to the ShinyHunters hacking group, said the hackers demanded a $55 cardinal ransom from the institution successful speech for not publically releasing the stolen files.

A spokesperson for McKesson did not respond to TechCrunch’s petition for remark connected Monday.

McKesson is the latest healthcare institution oregon aesculapian instrumentality shaper to beryllium targeted successful a drawstring of cyberattacks successful caller months, arsenic hackers purpose to bargain ample amounts of delicate aesculapian and wellness information that they tin usage to extort the companies into paying a ransom to support it from being published.

Last week, aesculapian instrumentality shaper Boston Scientific was deed by a cyberattack that knocked overmuch of the company’s web offline. The cyberattack had a akin effect to an incidental earlier this twelvemonth at different aesculapian instrumentality shaper Stryker, successful which hackers abused a company’s interior tools to remotely hitch thousands of worker devices. Abbott Laboratories and Medtronic person besides experienced cyberattacks, while physics diligent records supplier CareCloud and wellness tech institution TriZetto had breaches affecting implicit 3 cardinal patients each.

The ShinyHunters hackers person besides taken recognition for sizable information breaches at Amazon-owned OneMedical and dental security institution DentaQuest pursuing cyberattacks connected their systems.

Lorenzo Franceschi-Bicchierai contributed reporting.

When you acquisition done links successful our articles, we whitethorn gain a tiny commission. This doesn’t impact our editorial independence.

Read Entire Article