ShinyHunters expose 6.4M in attack on medical supplier McKesson
ShinyHunters leaked stolen McKesson data exposing roughly 6.4 million individuals after the medical supplier reportedly declined a $55.2 million extortion demand.
Have I Been Pwned added records leaked by ShinyHunters from medical and pharmaceutical supply company McKesson, confirming the August 2026 attack affected about 6.4 million people. Exposed data includes names, email and physical addresses, dates of birth, phone numbers, employer details, and sensitive health information; ShinyHunters claimed SSNs and 284 million documents were taken, though HIBP found no SSNs. The group issued a $55.2 million extortion demand that was apparently unpaid before publication. The article also notes Boston Scientific expects to miss Q3 guidance after its own attack, and that Veradigm disclosed attackers used third-party vendor credentials to access an API and steal roughly 3.5 million patient records claimed by ransomware group The Gentlemen.
- HIBP added ShinyHunters' leaked McKesson records, confirming 6.4 million affected individuals.
- Data includes names, addresses, dates of birth, employer details, and sensitive health information.
- ShinyHunters demanded $55.2 million; unpaid, they published data and claimed SSNs were stolen.
- Veradigm attackers used third-party vendor credentials to access an API and steal ~3.5M patient records.
- Boston Scientific expects to miss Q3 sales and earnings guidance after its separate cyberattack.
Full article414 words · extracted from theregister.com · click to collapse
Security
Have I Been Pwned logs leaked records spanning patients, staff, and providers
McKesson's cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP).
The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time.
ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP did not confirm that figure.
REG AD
The cybercriminals told The Register that they issued a $55.2 million extortion demand to prevent the release of McKesson's data – a sum that apparently was not paid, given the subsequent publication of the data.
REG AD
HIBP said: "The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff, and healthcare provider contacts."
The types of information exposed vary between individuals, but the records collectively include names, email and physical addresses, genders, dates of birth, phone numbers, employer details, and sensitive health information.
This is broadly consistent with ShinyHunters' claims that the stolen data included appointment dates and notes, as well as sensitive medical details such as the locations of patients' cancers.
ShinyHunters also claimed to have stolen Social Security numbers (SSNs) as part of the breach, but HIBP did not include these in its analysis of the leaked corpus.
The Register asked McKesson to comment on HIBP's assessment.
The company, which supports 3,300 oncology providers in 29 states, has not publicly confirmed the scale of the breach or issued further details since the last update from its CIO and CTO on August 29.
Medical device maker Boston Scientific disclosed a cyberattack at around the same time as McKesson, but has suffered a different kind of fallout.
While McKesson is informing the millions of individuals affected by its breach, Boston Scientific told shareholders that disruption from its attack means it expects to miss its sales and earnings guidance for Q3.
REG AD
An update issued on Wednesday said manufacturing, order fulfillment, and shipping operations had been fully restored, although work to restore some business applications continued.
Healthtech company Veradigm also disclosed a cyberattack to US regulators this week, days after ransomware group The Gentlemen claimed responsibility.
Veradigm said attackers obtained credentials from a third-party vendor's environment and used them to access a company API, stealing patient data without disrupting operations.
The Gentlemen claimed to have stolen around 3.5 million records containing personally identifiable information (PII), including SSNs. ®
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.theregister.com/security/2026/09/10/shinyhunters-expose-64m-in-attack-on-medical-supplier-mckesson/5295550