21 days ago
TechCrunch Aug 31, 2026

Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson

Healthcare giant McKesson disclosed a significant data breach last week, with hackers claiming to have stolen millions of patient records. The attack targeted McKesson’s cloud-hosted accounts, including Snowflake and Salesforce environments linked to its oncology, multispecialty, and medical-surgical units. A prolific hacking group known as ShinyHunters took responsibility for the intrusion, reportedly gaining access through phishing and social engineering tactics that compromised employee credentials. The stolen data encompasses sensitive patient information such as names, addresses, Social Security numbers, diagnoses, medications, allergies, and clinical notes, along with details of McKesson employees.

McKesson, based in Texas, is among the largest pharmaceutical distributors in the US, supplying medicines, medical supplies, and technology to hospitals and healthcare providers nationwide. The company acknowledged the breach publicly and warned of intermittent service disruptions as it addresses the incident. McKesson's CTO, Francisco Fraga, highlighted that the compromised data relates primarily to specific healthcare service units. However, the company declined to disclose the ransom demands or the exact number of individuals impacted. A spokesperson affirmed that business operations continue and McKesson believes there is no ongoing unauthorized access.

The ShinyHunters group reportedly demanded a $55 million ransom to prevent the public release of the stolen medical files. This breach adds to a troubling wave of cyberattacks on healthcare organizations and medical device manufacturers in recent months. Other prominent companies such as Boston Scientific, Stryker, Abbott Laboratories, Medtronic, and electronic health record providers CareCloud and TriZetto have faced similar incidents, resulting in the exposure of millions of patient records. These attacks often involve ransomware or extortion tactics designed to capitalize on the value of private medical data.

The attack on McKesson reflects a growing cybersecurity threat landscape targeting the healthcare sector, where personal health information is both plentiful and highly sensitive. Security experts warn that as threat actors continue to exploit social engineering and cloud vulnerabilities, healthcare companies must bolster defenses to protect patient privacy and critical infrastructure. While McKesson is working to contain the breach, the incident underscores the urgent need for stronger security measures in an industry increasingly reliant on digital systems.

0
0 Read source
Share this post
Facebook Twitter LinkedIn

Discussion

0 comments

No comments yet

Start the discussion with a take, question, or market read.