ZeroHour

Search: “mckesson”

77 stories

McKesson copes with fallout from data theft extortion attack

McKesson discloses a data theft extortion attack by ShinyHunters affecting oncology and medical-surgical customers, with a reported $55 million demand.

McKesson disclosed that attackers gained access to some of its third-party applications and stole data associated with a subset of customers in its oncology, multispecialty, and medical-surgical business units; the intrusion ran for four days from August 21 and was discovered August 25. ShinyHunters claimed responsibility and listed McKesson on its data-leak site, reportedly demanding more than $55 million with a September 1 deadline. Flashpoint analysts say the group typically uses social engineering and identity weaknesses with valid credentials to access cloud-hosted environments, making the intrusion hard to detect. McKesson, which distributes about one-third of pharmaceuticals used in North America with $403.4 billion in annual revenue, says operations continue and it has reasonable assurance of no ongoing unauthorized activity.

CyberScoop · 16d agoData breach in the wild

ShinyHunters claims it stole 284 million patient records from McKesson

ShinyHunters claims theft of 284 million patient records from McKesson via vishing, Okta takeover, and Salesforce/Snowflake access, demanding $55,236,150.

McKesson disclosed in an SEC filing a cybersecurity incident detected August 25, 2026, involving unauthorized access to third-party applications and data exfiltration affecting a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. ShinyHunters told BleepingComputer it entered through vishing calls to employees, used stolen credentials to take over Okta single sign-on accounts, and extracted about a terabyte of data from Salesforce and Snowflake environments over four days. The group claims 284 million database rows including names, addresses, Social Security numbers, Medicaid details, medical record numbers, and medication data, and demanded $55,236,150 with a 72-hour deadline; none of these claims have been independently verified.

Help Net Security · 17d agoData breach

Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack

Pharmaceutical giant McKesson disclosed a cyberattack on a third-party application that exfiltrated customer data, claimed by ShinyHunters.

McKesson reported a cybersecurity incident involving an unnamed third-party application, with attackers exfiltrating data tied to its oncology and surgical business units. The company filed with the SEC, offered credit monitoring, and said it had received reasonable assurance the attackers were no longer inside its systems. The ShinyHunters group claimed responsibility and threatened leaks; McKesson reported $106 billion in revenue last quarter and distributes about one-third of North American prescriptions.

The Record · 16d agoRansomware in the wild

ShinyHunters expose 6.4M in attack on medical supplier McKesson

ShinyHunters leaked stolen McKesson data exposing roughly 6.4 million individuals after the medical supplier reportedly declined a $55.2 million extortion demand.

Have I Been Pwned added records leaked by ShinyHunters from medical and pharmaceutical supply company McKesson, confirming the August 2026 attack affected about 6.4 million people. Exposed data includes names, email and physical addresses, dates of birth, phone numbers, employer details, and sensitive health information; ShinyHunters claimed SSNs and 284 million documents were taken, though HIBP found no SSNs. The group issued a $55.2 million extortion demand that was apparently unpaid before publication. The article also notes Boston Scientific expects to miss Q3 guidance after its own attack, and that Veradigm disclosed attackers used third-party vendor credentials to access an API and steal roughly 3.5 million patient records claimed by ransomware group The Gentlemen.

The Register · Securityupdated · 6d agofirst · 6d agoData breach 2 sources

Healthcare Giant McKesson Investigates Data Breach Incident

ShinyHunters claims theft of 284 million records from healthcare giant McKesson, which says it is investigating the alleged breach.

ShinyHunters claims it stole 284 million records from McKesson, one of the largest healthcare distribution companies. McKesson confirmed it is investigating a data breach incident. The claimed scale of the theft has not yet been independently verified, and extortion activity is implied by the actor's involvement.

Infosecurity Magazine · 15d agoData breach1

McKesson confirms cyber incident after ShinyHunters claims patient-data theft

Healthcare giant McKesson confirmed a cyber incident after ShinyHunters claimed theft of hundreds of millions of patient records.

McKesson acknowledged a data breach following public claims by the threat actor group ShinyHunters that it stole hundreds of millions of records containing patient data. The company confirmed a cyber incident occurred but the full scope of the theft has not yet been independently verified. ShinyHunters is known for large-scale data theft and extortion against major organizations. The healthcare sector remains a frequent target for data-theft extortion groups.

Malwarebytes Labs · 16d agoData breach

Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson

Hackers claim theft of millions of patient records from US healthcare distributor McKesson, which confirmed a hack and expects service degradation.

McKesson, which distributes medicines and medical devices to hospitals and healthcare practices across the US, said it was hacked. Threat actors claim millions of patient records were stolen in the breach. The company said it expects intermittent service degradation as it responds to the incident.

TechCrunch · Security · 16d agoData breach in the wild

Healthcare cyberattacks hit pacemakers and millions of patient records

McKesson confirms a data breach as ShinyHunters demands $55.2M amid healthcare cyberattacks affecting millions of patient records and pacemaker devices.

McKesson, one of the largest US healthcare distribution companies, has admitted a data breach. The ShinyHunters group is demanding a $55.2M extortion payment. The Register reports broader healthcare cyberattacks tied to the story, affecting millions of patient records and involving medical devices such as pacemakers. Details on the exact number of compromised records have not been confirmed.

The Register · Security · 16d agoData breach in the wild

Nutex Health Says Patient Data Stolen, Hackers Threaten Leak

The Gentlemen ransomware gang claims breach of US healthcare provider Nutex Health, exfiltrating patient and employee data and threatening publication.

Nutex Health disclosed in an SEC 8-K filing that an unauthorized third party accessed and exfiltrated patient, employee, credentialed provider, business, and financial data from company servers, and threatened to publish it. The Gentlemen ransomware group listed Nutex on its leak site; a class action was filed August 27 and Edelson Lechtzin LLP is separately investigating. Nutex operates over 27 facilities in 12 states and served nearly 100,000 patients in the first half of 2026, with no material operational impact identified so far.

Infosecurity Magazine · 14d agoRansomware

Florida says motor vehicle data breach tied to credentials stolen from officer’s personal device

ShinyHunters breached Florida's DMV using credentials stolen from a police officer's personal device; the state confirmed the breach and is investigating.

Florida's Department of Highway Safety and Motor Vehicles (FLHSMV) confirmed a data breach after ShinyHunters obtained DMV data using credentials a criminal actor took from a Plant City police officer's personal electronic device. The department learned of the breach on September 4, is investigating with the Florida Digital Service, and ShinyHunters shared a DMV record of Jeffrey Epstein as proof of access. Experts initially speculated a link to the IDScan breach of 153 million driver's licenses. Anthropic reported that suspected ShinyHunters affiliates use AI to scan credentials, map systems, and exfiltrate data, in one case moving from a stolen developer token to cloud admin access in about three hours.

The Recordupdated · 7h agofirst · 5d agoData breach in the wild 3 sources

AdaptHealth confirms 4.1 million people exposed in July cyberattack

AdaptHealth confirmed a ShinyHunters-attributed cyberattack exposed data of 4.1 million patients via a compromised third-party contractor account.

Healthcare company AdaptHealth confirmed 4,115,802 individuals were exposed in an intrusion first disclosed in an SEC filing on July 2, 2026, with the compromise beginning June 5. Attackers used social engineering to compromise a privileged third-party contractor account, accessed cloud-based patient management, document storage and EHR portals, and exfiltrated names, contact details, demographic, insurance and health information before a June 15 ransom demand. The attack was attributed to the ShinyHunters group, though the company no longer appears on the gang's extortion portal. Impacted individuals are being offered 12 months of free credit monitoring and identity protection.

BleepingComputer · 7d agoData breach1

Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

Microsoft patches 974 flaws in record Patch Tuesday, including two actively exploited Windows zero-days enabling privilege escalation.

Microsoft's largest-ever Patch Tuesday addresses 974 vulnerabilities, with CVE-2026-81963 (Windows Update Stack) and CVE-2026-85880 (Windows Advanced Local Procedure Call) exploited before disclosure. Both zero-days carry CVSS 7.8 ratings and allow privilege escalation. More than 10% of the defects are rated critical, and researchers attribute the record volume to AI-assisted vulnerability discovery without a matching rise in active exploitation.

CyberScoop · 8d agoExploit / PoC in the wildCVE-2026-81963CVE-2026-85880

Feds accuse China of ‘systematic’ distillation of U.S. AI models

NSA, CISA, and FBI jointly accuse Chinese AI firms including DeepSeek and Moonshot AI of industrial-scale distillation of US frontier models.

A joint advisory from the NSA, CISA, and FBI alleges China-based AI companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have systematically extracted capabilities from US frontier models since at least late 2024. The companies allegedly spent billions of tokens across millions of requests against Claude, ChatGPT, Gemini, and Grok, routing traffic through multiple accounts, platforms, proxies, and third-party aggregators to evade detection. Moonshot AI allegedly distilled 18 US models, including Anthropic's most advanced model, to train its Kimi-K2 and Kimi K3 models.

CyberScoop · 8d agoAI policy

Attackers exploit zero-days in consistently besieged SonicWall product

Two actively exploited SonicWall SMA 1000 zero-days chain to unauthenticated RCE; patches released and CISA added both to KEV.

SonicWall disclosed and patched two zero-days in SMA 1000 appliances: CVE-2026-83548, a maximum-severity pre-authentication SSRF, and CVE-2026-83549, a high-severity OS command injection. Rapid7 said chaining the flaws yields unauthenticated remote code execution, and CISA added both to its KEV catalog Wednesday. The vendor provided no IOCs or victim counts, urging customers to hunt for compromise, reimage or redeploy appliances, and reset all passwords and tokens. The product has faced repeated exploitation, including ransomware-linked flaws used by INC and Akira.

CyberScoop · 13d agoExploit / PoC in the wildCVE-2026-83548CVE-2026-83549

Health data of more than 9.5 million people leaked from Aesto record system

Health data firm Aesto reported a breach affecting over 9.5 million people after hackers accessed its AWS infrastructure between December 2 and 18.

Alabama-based healthcare data company Aesto notified the Department of Health and Human Services that more than 9.5 million people had sensitive information leaked in a December cyberattack, after previously warning customers in June without disclosing scope. Attackers broke into the company's Amazon Web Services infrastructure between December 2 and December 18, stealing names, Social Security numbers, medical information, driver's license numbers, financial account numbers, and health insurance data. Aesto provides data migration and archiving services for medical facilities, and at least 30 healthcare organizations were affected, with breach notices filed for customers including Together Women's Health. Related healthcare incidents disclosed this year include Baylor Genetics (2.8 million people), CareCloud (3.7 million), and recent attacks at McKesson, Nutex, Paylogix, and Park Dental Partners.

The Record · 14d agoData breach

Pegasus, NoviSpy variant spyware found on devices of Serbian activists

Researchers confirmed the first 2026 Pegasus infection and a new NoviSpy variant on 14 Serbian activists, likely surveillance by Serbian authorities ahead of elections.

Citizen Lab confirmed with high probability the first forensically confirmed Pegasus infection of 2026, on a Serbian student activist hacked via a zero-click exploit between December of last year and January. Amnesty International confirmed two devices infected with a new NoviSpy variant, and the SHARE Foundation documented 14 targets including a member of parliament and a local government official, the largest documented spyware wave in Serbia to date. Evidence points to Serbian police or intelligence services, with NoviSpy infections occurring around police detention ahead of key local and parliamentary elections. Apple threat notifications preceded the findings, and updated iOS versions break the exploit chain.

CyberScoop · 14d agoThreat actor in the wild