{"id":1035520,"date":"2026-08-31T20:00:26","date_gmt":"2026-08-31T20:00:26","guid":{"rendered":"https:\/\/www.europesays.com\/us\/1035520\/"},"modified":"2026-08-31T20:00:26","modified_gmt":"2026-08-31T20:00:26","slug":"hackers-claim-millions-of-patient-records-stolen-during-data-breach-at-healthcare-giant-mckesson","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/us\/1035520\/","title":{"rendered":"Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson"},"content":{"rendered":"<p id=\"speakable-summary\" class=\"wp-block-paragraph\">A prolific hacking group has taken credit for last week\u2019s cyberattack against U.S. pharmaceutical distribution giant McKesson, leading to the latest spill of highly sensitive health data by an American healthcare company in recent months.<\/p>\n<p class=\"wp-block-paragraph\">McKesson confirmed Friday in a <a href=\"https:\/\/www.mckesson.com\/utility\/cybersecurity\/customer-cybersecurity-information-center\/#update\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">statement on its website<\/a> that hackers broke into several of its cloud-hosted accounts earlier in the week and exfiltrated data, and that the company expected \u201cintermittent service degradation\u201d related to the incident. In a separate notice to customers, the company\u2019s chief technology officer, Francisco Fraga, said the stolen data relates to its oncology &amp; multispecialty and medical-surgical units.<\/p>\n<p class=\"wp-block-paragraph\">The Texas-based company is one of the largest American distributors of pharmaceuticals, medicines, medical supplies, and technology to hospitals and healthcare providers across the United States, and as such handles a large amount of patient data.<\/p>\n<p class=\"wp-block-paragraph\">The ShinyHunters hacking group \u2014 one of the most active data-extortion crews of the past two years \u2014 told TechCrunch that it hacked the company\u2019s cloud environment by tricking several employees into granting the hackers access to McKesson\u2019s network by using phishing and social engineering tricks, which the group is known for.<\/p>\n<p class=\"wp-block-paragraph\">The hackers said they stole a range of personal information, such as names, addresses, and Social Security numbers, as well as protected health information, including diagnoses, medications, allergies, and patient notes. The hackers say they took millions of rows of patient data from the company\u2019s cloud-hosted Snowflake and Salesforce environments, but that they are unsure of how many individuals are ultimately affected.<\/p>\n<p class=\"wp-block-paragraph\">The stolen data also included McKesson employees\u2019 information, such as home addresses.<\/p>\n<p class=\"wp-block-paragraph\">ShinyHunters shared screenshots and a sample of the stolen data with TechCrunch, and we verified a small subset of it against public records.<\/p>\n<p class=\"wp-block-paragraph\">Bleeping Computer, which <a href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">first reported the link<\/a> to the ShinyHunters hacking group, said the hackers demanded a $55 million ransom from the company in exchange for not publicly releasing the stolen files.<\/p>\n<p class=\"wp-block-paragraph\">In a statement, McKesson spokesperson Kristina Chang said the company \u201ccontinues to operate in all lines of business,\u201d and reiterated its public statement, and noted that McKesson believes it has no ongoing unauthorized activity in its systems. The company would not answer TechCrunch\u2019s questions about the incident, such as what the hackers demanded or how many individuals had data affected by the incident.<\/p>\n<p class=\"wp-block-paragraph\">McKesson is the latest healthcare company or medical device maker to be targeted in a string of cyberattacks in recent months, as hackers aim to steal large amounts of sensitive medical and health data that they can use to extort the companies into paying a ransom to keep it from being published.<\/p>\n<p class=\"wp-block-paragraph\">Last week, medical device maker Boston Scientific was <a href=\"https:\/\/techcrunch.com\/2026\/08\/26\/medical-device-maker-boston-scientific-says-a-cyberattack-is-causing-a-global-disruption-to-its-operations\/\" rel=\"nofollow noopener\" target=\"_blank\">hit by a cyberattack<\/a> that knocked much of the company\u2019s network offline. The cyberattack had a similar effect to an incident earlier this year at <a href=\"https:\/\/techcrunch.com\/2026\/03\/17\/stryker-says-its-restoring-systems-after-pro-iran-hackers-wiped-thousands-of-employee-devices\/\" rel=\"nofollow noopener\" target=\"_blank\">another medical device maker Stryker<\/a>, in which hackers abused a company\u2019s internal tools to remotely wipe thousands of employee devices. Abbott Laboratories and Medtronic have also experienced cyberattacks, while <a href=\"https:\/\/techcrunch.com\/2026\/08\/19\/carecloud-confirms-3-7m-patients-had-their-medical-records-stolen-in-data-breach\/\" rel=\"nofollow noopener\" target=\"_blank\">electronic patient records provider CareCloud<\/a> and <a href=\"https:\/\/techcrunch.com\/2026\/03\/06\/trizetto-confirms-3-4m-peoples-health-and-personal-data-was-stolen-during-breach\/\" rel=\"nofollow noopener\" target=\"_blank\">health tech company TriZetto<\/a> had breaches affecting over 3 million patients each.<\/p>\n<p class=\"wp-block-paragraph\">The ShinyHunters hackers have also taken credit for sizable data breaches at <a href=\"https:\/\/www.fiercehealthcare.com\/health-tech\/one-medical-seniors-reports-data-breach-third-party-file-storage-system\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Amazon-owned One Medical<\/a> and dental <a href=\"https:\/\/www.hipaajournal.com\/dentaquest-data-breach\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">insurance company DentaQuest<\/a> following cyberattacks on their systems.<\/p>\n<p class=\"wp-block-paragraph\">Lorenzo Franceschi-Bicchierai contributed reporting. Updated with comment from a McKesson spokesperson.<\/p>\n<p>When you purchase through links in our articles, <a href=\"https:\/\/techcrunch.com\/techcrunch-affiliate-monetization-standards\/\" rel=\"nofollow noopener\" target=\"_blank\">we may earn a small commission<\/a>. This doesn\u2019t affect our editorial independence.<\/p>\n","protected":false},"excerpt":{"rendered":"A prolific hacking group has taken credit for last week\u2019s cyberattack against U.S. pharmaceutical distribution giant McKesson, leading&hellip;\n","protected":false},"author":3,"featured_media":1035521,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_share_on_mastodon":"0"},"categories":[35],"tags":[14461,734,13805,210,1141,1142,67,132,68],"class_list":["post-1035520","post","type-post","status-publish","format-standard","has-post-thumbnail","category-health-care","tag-cyberattack","tag-cybersecurity","tag-data-breach","tag-health","tag-health-care","tag-healthcare","tag-united-states","tag-unitedstates","tag-us"],"share_on_mastodon":{"url":"","error":""},"_links":{"self":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/1035520","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/comments?post=1035520"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/posts\/1035520\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media\/1035521"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/media?parent=1035520"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/categories?post=1035520"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/us\/wp-json\/wp\/v2\/tags?post=1035520"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}