ESPNHokies name PSU transfer Grunkemeyer top QBESPN DeportesFlick repite lista de Barcelona con cuatro ausencias ante RayoThe Jerusalem PostFinland's Israel policy might be driven by upcoming elections, expert tells 'Post' - interviewRTP DesportoPortugal eliminado pela Polónia nos `oitavos` do Europeu feminino de voleibolוואלההפגנה בכניסה לירושלים: מפגינים חוסמים לסירוגין את הכבישיםSCMP ChinaUS targets China’s global trade surplus at G20 meeting ahead of Xi-Trump summitسكاي نيوز عربيةتقرير: ترامب يدرس توجيه ضربات محدودة "لردع إيران"ynet ספורטחי, מחצית שנייה: מכבי ת"א – מכבי חיפה 0:3QuemPussycat Dolls anuncia Pabllo Vittar como atração de abertura de seu 1º show no BrasilNTVSayısal Loto sonuçları açıklandı: Dev ikramiye sahibini buldu mu? 24 Ağustos 2026 MPİ Çılgın Sayısal Loto bilet sorgulama ekranıOnetKomisja śledcza w sprawie Zondacrypto? Czarnek odpowiada na pomysł MorawieckiegoWirtualna PolskaŚmigłowiec uderzył w linię i odleciał. Trwa poszukiwanie pilota
The Daily Newsstand · Free, Always
Monday, August 31, 2026

Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson

Translate

A prolific hacking group has taken credit for last week’s cyberattack against U.S. pharmaceutical distribution giant McKesson, leading to the latest spill of highly sensitive health data by an American healthcare company in recent months.

McKesson confirmed Friday in a statement on its website that hackers broke into several of its cloud-hosted accounts earlier in the week and exfiltrated data, and that the company expected “intermittent service degradation” related to the incident. In a separate notice to customers, the company’s chief technology officer, Francisco Fraga, said the stolen data relates to its oncology & multispecialty and medical-surgical units.

The Texas-based company is one of the largest American distributors of pharmaceuticals, medicines, medical supplies, and technology to hospitals and healthcare providers across the United States, and as such handles a large amount of patient data.

The ShinyHunters hacking group — one of the most active data-extortion crews of the past two years — told TechCrunch that it hacked the company’s cloud environment by tricking several employees into granting the hackers’ access to McKesson’s network by using phishing and social engineering tricks, which the group is known for.

The hackers said they stole a range of personal information, such as names, addresses, and Social Security numbers, as well as protected health information, including diagnoses, medications, allergies, and patient notes. The hackers say they took millions of rows of patient data from the company’s cloud-hosted Snowflake and Salesforce environments, but that they are unsure of how many individuals are ultimately affected.

The stolen data also included McKesson employees’ information, such as home addresses.

ShinyHunters shared screenshots and a sample of the stolen data with TechCrunch, and we verified a small subset of it against public records.

Bleeping Computer, which first reported the link to the ShinyHunters hacking group, said the hackers demanded a $55 million ransom from the company in exchange for not publicly releasing the stolen files.

A spokesperson for McKesson did not respond to TechCrunch’s request for comment on Monday.

McKesson is the latest healthcare company or medical device maker to be targeted in a string of cyberattacks in recent months, as hackers aim to steal large amounts of sensitive medical and health data that they can use to extort the companies into paying a ransom to keep it from being published.

Last week, medical device maker Boston Scientific was hit by a cyberattack that knocked much of the company’s network offline. The cyberattack had a similar effect to an incident earlier this year at another medical device maker Stryker, in which hackers abused a company’s internal tools to remotely wipe thousands of employee devices. Abbott Laboratories and Medtronic have also experienced cyberattacks, while electronic patient records provider CareCloud and health tech company TriZetto had breaches affecting over 3 million patients each.

The ShinyHunters hackers have also taken credit for sizable data breaches at Amazon-owned OneMedical and dental insurance company DentaQuest following cyberattacks on their systems.

Lorenzo Franceschi-Bicchierai contributed reporting.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Zack Whittaker is the security editor at TechCrunch. He also authors the weekly cybersecurity newsletter, this week in security.

He can be reached via encrypted message at zackwhittaker.1337 on Signal. You can also contact him by email, or to verify outreach, at zack.whittaker@techcrunch.com.

View the original on TechCrunch

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.