Breaking
ESThe White House confirms the privatization of Venezuela's hydrocarbon sectorARSecurity and military developments: Russia warns Japan, attacks in Ukraine, and an investigation into a factory fire in PolandPLWave of false bomb alarms in Russia before September 1KRAndong Mayor Kwon Ki-chang's younger brother arrested on suspicion of soliciting party member recruitment ahead of the People Power Party primaryKR3 people died due to heavy rain nationwide... Facility damage and evacuation continuedINTLIsraeli attacks in Gaza kill at least four peopleRUUS Army Secretary Dan Driscoll resignsDENorway's new King Haakon VIII takes oath without Mette-MaritKRHD Hyundai Heavy Industries' first labor-management wage agreement negotiations collapse... Union strike beginsRUThe Russian Foreign Ministry recommended that Russians refrain from traveling to northern NepalESThe White House confirms the privatization of Venezuela's hydrocarbon sectorARSecurity and military developments: Russia warns Japan, attacks in Ukraine, and an investigation into a factory fire in PolandPLWave of false bomb alarms in Russia before September 1KRAndong Mayor Kwon Ki-chang's younger brother arrested on suspicion of soliciting party member recruitment ahead of the People Power Party primaryKR3 people died due to heavy rain nationwide... Facility damage and evacuation continuedINTLIsraeli attacks in Gaza kill at least four peopleRUUS Army Secretary Dan Driscoll resignsDENorway's new King Haakon VIII takes oath without Mette-MaritKRHD Hyundai Heavy Industries' first labor-management wage agreement negotiations collapse... Union strike beginsRUThe Russian Foreign Ministry recommended that Russians refrain from traveling to northern Nepal
BackShinyHunters claims responsibility for cyberattack on U.S. healthcare giant McKesson
ShinyHunters claims responsibility for cyberattack on U.S. healthcare giant McKesson
Developing
TechCrunch2 hours agoTech2 min readUnited States

ShinyHunters claims responsibility for cyberattack on U.S. healthcare giant McKesson

Hackers stole sensitive health data and employee information, demanding a $55 million ransom.

Quick Look

Prolific hacking group ShinyHunters claimed responsibility for a cyberattack on U.S. pharmaceutical distributor McKesson, stealing sensitive patient and employee data and demanding a $55 million ransom.

AI-generated summary

Why It Matters

A prolific hacking group accessed cloud-hosted accounts of pharmaceutical distributor McKesson, exfiltrating sensitive health data.

Font size

A prolific hacking group has taken credit for last week’s cyberattack against U.S. pharmaceutical distribution giant McKesson, leading to the latest spill of highly sensitive health data by an American healthcare company in recent months.

McKesson confirmed Friday in a statement on its website that hackers broke into several of its cloud-hosted accounts earlier in the week and exfiltrated data, and that the company expected “intermittent service degradation” related to the incident. In a separate notice to customers, the company’s chief technology officer, Francisco Fraga, said the stolen data relates to its oncology & multispecialty and medical-surgical units.

The Texas-based company is one of the largest American distributors of pharmaceuticals, medicines, medical supplies, and technology to hospitals and healthcare providers across the United States, and as such handles a large amount of patient data.

The ShinyHunters hacking group — one of the most active data-extortion crews of the past two years — told TechCrunch that it hacked the company’s cloud environment by tricking several employees into granting the hackers access to McKesson’s network by using phishing and social engineering tricks, which the group is known for.

The hackers said they stole a range of personal information, such as names, addresses, and Social Security numbers, as well as protected health information, including diagnoses, medications, allergies, and patient notes. The hackers say they took millions of rows of patient data from the company’s cloud-hosted Snowflake and Salesforce environments, but that they are unsure of how many individuals are ultimately affected.

The stolen data also included McKesson employees’ information, such as home addresses.

ShinyHunters shared screenshots and a sample of the stolen data with TechCrunch, and we verified a small subset of it against public records.

Bleeping Computer, which first reported the link to the ShinyHunters hacking group, said the hackers demanded a $55 million ransom from the company in exchange for not publicly releasing the stolen files.

In a statement, McKesson spokesperson Kristina Chang said the company “continues to operate in all lines of business,” and reiterated its public statement, and noted that McKesson believes it has no ongoing unauthorized activity in its systems. The company would not answer TechCrunch’s questions about the incident, such as what the hackers demanded or how many individuals had data affected by the incident.

McKesson is the latest healthcare company or medical device maker to be targeted in a string of cyberattacks in recent months, as hackers aim to steal large amounts of sensitive medical and health data that they can use to extort the companies into paying a ransom to keep it from being published.

Last week, medical device maker Boston Scientific was hit by a cyberattack that knocked much of the company’s network offline. The cyberattack had a similar effect to an incident earlier this year at another medical device maker Stryker, in which hackers abused a company’s internal tools to remotely wipe thousands of employee devices. Abbott Laboratories and Medtronic have also experienced cyberattacks, while electronic patient records provider CareCloud and health tech company TriZetto had breaches affecting over 3 million patients each.

The ShinyHunters hackers have also taken credit for sizable data breaches at Amazon-owned One Medical and dental insurance company DentaQuest following cyberattacks on their systems.

Open Questions

  • How many individuals are ultimately affected by the breach?
  • Will McKesson pay the $55 million ransom?

Related Topics

This article was originally published by TechCrunch.

Related Stories

Clipto raises $15M to build AI-powered file search tool for personal computers
Developing·4 hours ago

Clipto raises $15M to build AI-powered file search tool for personal computers

Clipto, a San Francisco-based startup with teams in Singapore and Hong Kong, has raised $15 million in an all-equity round at a $250 million post-money valuation to develop its AI-powered file search tool that helps users find videos, audio, images, and documents on their personal computers using natural language queries. The company, founded by Henry Kang in 2023, reports over 30 million users and hundreds of thousands of paying subscribers, reached $15 million in annual recurring revenue in early 2026, and remains profitable. The funding will support AI model development, computing infrastructure for consumer hardware, and integrations with more AI agents.

TechCrunch
2 min read
More on this topicmckesson