McKesson Confirms Major Data Breach as Hackers Threaten to Leak Customer Records
Leave a Comment / Cybersecurity, Data Protection, Enterprise Technology, Industry News / By cxojunction
Healthcare giant Mckesson Corporation has confirmed that hackers exfiltrated customer data from its systems, prompting an investigation as the attackers threaten to release the stolen information. The incident was discovered on August 25 and involved third-party applications and data theft.

The healthcare giant said the unauthorized activity affected a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units. The unauthorized access has since been disrupted, while its services, systems, and network capabilities remain operational. The company also said it will provide complimentary credit monitoring and identity protection services to impacted individuals.
The organization has not disclosed the type of data stolen, the number of individuals affected, or confirmed who was behind the attack. However, the ShinyHunters extortion group has added the company to its Tor-based leak site and threatened to release the information unless ransom negotiations begin by September 1. The group reportedly claims to have stolen 284 million customer records and demanded approximately $55 million. The allegedly compromised information includes PII, PHI, medical and treatment information, prescription and billing records, employee records, and information related to customer physicians and clinics.
The company said it immediately activated its incident response protocols, launched an investigation, and engaged leading cybersecurity experts to support its response. It has reasonable assurance that there is no ongoing unauthorized activity in its systems and continues to monitor the environment while determining the full scope of information that may have been accessed or acquired.
For organizations, the incident highlights the importance of strong third-party security controls, continuous monitoring, rapid incident response, and effective data-protection measures. These capabilities can help limit unauthorized access, safeguard sensitive information, reduce operational and financial impact, and strengthen resilience against data-extortion attacks.
CXO Junction remains dedicated to providing you with exclusive insights into transformative leadership journeys. Stay tuned for more updates as we continue to bring industry news to you.
Source: McKesson Confirms Data Breach as Attacker Deadline Looms | SECURITYWEEK | https://www.securityweek.com/mckesson-confirms-data-breach-as-attacker-deadline-looms/
