VMTech
Discuss a project

McKesson confirms cloud account breach affecting healthcare data

McKesson confirms cloud account breach affecting healthcare data

McKesson has confirmed that attackers breached several of its cloud-hosted accounts and exfiltrated data, affecting its oncology & multispecialty and medical-surgical business units. The US pharmaceutical distribution company said it expected intermittent service degradation linked to the incident.

ShinyHunters, a data-extortion group active in recent years, claimed responsibility for the attack. The group told TechCrunch that it obtained access after using phishing and social-engineering tactics to convince several employees to grant access to McKesson’s network.

Claims of millions of patient-data rows

The attackers said they took millions of rows of patient data from McKesson’s cloud-hosted Snowflake and Salesforce environments. They said they did not know how many individuals were ultimately affected, so the number of people involved has not been established.

The alleged stolen information includes names, addresses and Social Security numbers, as well as protected health information such as diagnoses, medications, allergies and patient notes. ShinyHunters also said the material includes employee information, including home addresses.

The group shared screenshots and a sample of the purported data with TechCrunch, which verified a small subset against public records. Bleeping Computer reported that the attackers demanded a $55 million ransom in exchange for not publicly releasing the files. McKesson did not respond to a request for comment reported on Monday.

Cloud access is a high-value target

McKesson distributes pharmaceuticals, medicines, medical supplies and technology to hospitals and healthcare providers across the United States. Its position in that supply chain means its systems handle substantial volumes of patient information, making access to its cloud accounts especially consequential.

The incident follows a series of attacks on healthcare companies and medical-device makers. Boston Scientific recently experienced an attack that took much of its network offline, while Stryker faced an incident in which attackers abused internal tools to remotely wipe thousands of employee devices. Abbott Laboratories, Medtronic, CareCloud and TriZetto have also experienced cyberattacks or breaches.

Business implication

Healthcare organizations should treat employee-mediated cloud access as a core security boundary: use phishing-resistant authentication, restrict permissions to the minimum required, and monitor high-value data platforms such as Snowflake and Salesforce for unusual access and export activity.

#cybersecurity#healthcare#databreach#cloudsecurity
Open analytics
On the site 0 views
min read 3 31.08.2026
Instagram

McKesson confirms cloud account breach affecting healthcare data

Open the post on Instagram ↗