McKesson breach confirmed after ShinyHunters claim data theft

← Back to articles

McKesson breach confirmed after ShinyHunters claim data theft

McKesson has confirmed a cybersecurity incident that involved unauthorized access to third‑party applications and the theft of patient data, after the hacker group ShinyHunters claimed to have exfiltrated 284 million records. The company disclosed the breach in a statement to regulators and is working with law‑enforcement agencies to investigate the incident.

The breach affects patients whose information is stored in systems used by McKesson’s pharmacy and health‑care distribution services. According to the extortion group, the stolen data includes names, dates of birth, addresses, phone numbers and, in some cases, health‑insurance details. The claim has not been independently verified, but McKesson’s admission of unauthorized access suggests that some portion of the data may have been compromised.

ShinyHunters typically threatens to release stolen data unless a ransom is paid, a tactic that can lead to phishing emails, credential‑selling sites and identity‑theft scams. Victims may receive fraudulent messages that appear to come from health providers or insurers, asking for personal information or payment to “secure” their records. The group’s history shows they often post data on underground forums, where it can be harvested for further scams.

If you suspect your health information may be part of this breach, monitor your accounts for unexpected activity and be wary of unsolicited communications that request personal details. Use a strong, unique password for each online service and enable two‑factor authentication wherever possible. Free tools such as the password‑strength checker and identity‑theft monitoring service available at ComputerScams.com can help you spot compromised credentials early.

Regularly review credit reports and consider placing a fraud alert or credit freeze if you notice unfamiliar entries. Keep software and mobile apps up to date to reduce the risk of malware that could capture login information. When you receive an email or text that claims to be from a medical provider, verify the sender by contacting the organization directly using a known phone number or website, not the contact details in the message.

The incident underscores the importance of vigilant cyber security practices, especially for individuals whose personal health information is stored with large service providers. Staying informed and using available free security tools can reduce the chances of becoming a victim of follow‑up scams.

Source: Read the original report

Practical tip: Immediately change passwords for any online accounts that use the same email address as your health‑care portal, and enable two‑factor authentication.

Scroll to Top