Monday, 31 August 2026
Rīga TV

World and Latvian news in one place

TechnologyPublished: 31 August 2026 at 21:28

Hacking group ShinyHunters claims credit for data theft at pharmaceutical giant McKesson

The ShinyHunters hacking group says it stole millions of patient data records from U.S. pharmaceutical distributor McKesson after breaking into several of the company's cloud accounts. McKesson has confirmed the intrusion and warned of possible service disruptions.

Foto: TechCrunch

U.S. pharmaceutical and medical supply distribution giant McKesson confirmed on Friday, in a statement on its website, that hackers broke into several of its cloud-hosted accounts earlier in the week and extracted data. The company warned customers to expect intermittent service degradation as a result of the incident.

In a separate notice, McKesson's chief technology officer, Francisco Fraga, said the stolen data relates to the company's oncology & multispecialty and medical-surgical business units. Texas-based McKesson is one of the largest U.S. distributors of pharmaceuticals, medical supplies, and technology to hospitals and healthcare providers, meaning it handles vast amounts of patient data.

The ShinyHunters hacking group, one of the most active data-extortion crews of the past two years, told TechCrunch it gained access to McKesson's cloud environment by using phishing and social engineering to trick employees into granting network access — tactics the group is known for. The hackers claim to have stolen personal information such as names, addresses, and Social Security numbers, along with protected health information including diagnoses, medications, allergies, and patient notes.

According to the hackers, millions of rows of patient data were taken from McKesson's cloud-hosted Snowflake and Salesforce environments, though they say they are unsure how many individuals are ultimately affected. The stolen data reportedly also includes McKesson employees' personal information, such as home addresses. ShinyHunters shared screenshots and a data sample with TechCrunch, which verified a small subset against public records.

Bleeping Computer, which first reported the link to ShinyHunters, said the hackers demanded a $55 million ransom from McKesson in exchange for not publishing the stolen files. McKesson did not respond to a request for comment on Monday.

McKesson is the latest in a string of healthcare-sector companies targeted by cyberattacks in recent months. Medical device maker Boston Scientific was hit by a cyberattack last week that took much of its network offline, echoing an earlier incident this year at Stryker. Abbott Laboratories and Medtronic have also been targeted, while electronic patient records provider CareCloud and health tech company TriZetto each suffered breaches affecting more than 3 million patients. ShinyHunters has also previously claimed responsibility for breaches at Amazon-owned OneMedical and dental insurer DentaQuest.

Comments

0/1500

Comments are automatically moderated. No hate, threats, personal data or spam.

Loading comments…

More in this category