Security
Have I Been Pwned logs leaked records spanning patients, staff, and providers
McKesson's cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP).
The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time.
ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP did not confirm that figure.
The cybercriminals told The Register that they issued a $55.2 million extortion demand to prevent the release of McKesson's data – a sum that apparently was not paid, given the subsequent publication of the data.
HIBP said: "The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff, and healthcare provider contacts."
The types of information exposed vary between individuals, but the records collectively include names, email and physical addresses, genders, dates of birth, phone numbers, employer details, and sensitive health information.
This is broadly consistent with ShinyHunters' claims that the stolen data included appointment dates and notes, as well as sensitive medical details such as the locations of patients' cancers.
ShinyHunters also claimed to have stolen Social Security numbers (SSNs) as part of the breach, but HIBP did not include these in its analysis of the leaked corpus.
The Register asked McKesson to comment on HIBP's assessment.
The company, which supports 3,300 oncology providers in 29 states, has not publicly confirmed the scale of the breach or issued further details since the last update from its CIO and CTO on August 29.
Medical device maker Boston Scientific disclosed a cyberattack at around the same time as McKesson, but has suffered a different kind of fallout.
While McKesson is informing the millions of individuals affected by its breach, Boston Scientific told shareholders that disruption from its attack means it expects to miss its sales and earnings guidance for Q3.
An update issued on Wednesday said manufacturing, order fulfillment, and shipping operations had been fully restored, although work to restore some business applications continued.
Healthtech company Veradigm also disclosed a cyberattack to US regulators this week, days after ransomware group The Gentlemen claimed responsibility.
Veradigm said attackers obtained credentials from a third-party vendor's environment and used them to access a company API, stealing patient data without disrupting operations.
The Gentlemen claimed to have stolen around 3.5 million records containing personally identifiable information (PII), including SSNs. ®

5 hours ago
12








English (US) ·