Skip to content
TechCrunch·

🔒ShinyHunters Hack McKesson, Steal Millions of Patient Records

Hackers Exfiltrate Millions of Patient Records from McKesson

TL;DR

ShinyHunters hacked McKesson, stealing millions of patient records from Snowflake and Salesforce. The hackers demanded a $55 million ransom and threatened to release the data publicly. This breach highlights the growing threat of healthcare data theft.

ShinyHunters, a prolific hacking group, breached McKesson's cloud environment, stealing millions of patient records from Snowflake and Salesforce. The hackers demanded a $55 million ransom and threatened to release the data publicly. This breach affects healthcare providers and patients, as McKesson handles a large amount of sensitive medical and health data. The stolen data includes names, addresses, Social Security numbers, diagnoses, medications, allergies, and patient notes. The hackers used phishing and social engineering to trick employees into granting access. This incident underscores the critical need for robust security measures in cloud-hosted environments.

ShinyHunters Hack McKesson, Steal Millions of Patient Records — TechCrunch

Key Points

1

ShinyHunters breached McKesson's cloud-hosted Snowflake and Salesforce environments, stealing millions of patient records.

2

The hackers demanded a $55 million ransom from McKesson in exchange for not releasing the stolen data publicly.

3

The stolen data includes names, addresses, Social Security numbers, diagnoses, medications, allergies, and patient notes.

4

McKesson is one of the largest American distributors of pharmaceuticals, medicines, medical supplies, and technology to hospitals and healthcare providers.

5

The hackers used phishing and social engineering tactics to trick McKesson employees into granting access to their cloud-hosted accounts.

Why It Matters

This breach affects healthcare providers and patients as McKesson handles a large amount of sensitive medical and health data. The stolen data includes patient notes and diagnoses. The hackers used phishing and social engineering tactics to trick employees into granting access, highlighting the need for robust security measures in cloud-hosted environments.

ShinyHuntersMcKessonpatient datacyberattackcloud security

Frequently Asked Questions

Why does this matter?

This breach affects healthcare providers and patients as McKesson handles a large amount of sensitive medical and health data. The stolen data includes patient notes and diagnoses. The hackers used phishing and social engineering tactics to trick employees into granting access, highlighting the need for robust security measures in cloud-hosted environments.

What happened?

ShinyHunters hacked McKesson, stealing millions of patient records from Snowflake and Salesforce. The hackers demanded a $55 million ransom and threatened to release the data publicly. This breach highlights the growing threat of healthcare data theft.

Comments

Subscribe to join the conversation...

Be the first to comment

Enjoyed this article?

Get it daily. 7am. Free. Reads in 5 minutes.

Join 3,437 builders reading daily.

Also get