McKesson copes with fallout from data theft extortion attack
McKesson discloses a data theft extortion attack by ShinyHunters affecting oncology and medical-surgical customers, with a reported $55 million demand.
McKesson disclosed that attackers gained access to some of its third-party applications and stole data associated with a subset of customers in its oncology, multispecialty, and medical-surgical business units; the intrusion ran for four days from August 21 and was discovered August 25. ShinyHunters claimed responsibility and listed McKesson on its data-leak site, reportedly demanding more than $55 million with a September 1 deadline. Flashpoint analysts say the group typically uses social engineering and identity weaknesses with valid credentials to access cloud-hosted environments, making the intrusion hard to detect. McKesson, which distributes about one-third of pharmaceuticals used in North America with $403.4 billion in annual revenue, says operations continue and it has reasonable assurance of no ongoing unauthorized activity.
Extortion Group FulcrumSec Claims 86GB Manchester Airports Data Theft
Extortion group FulcrumSec claims stealing 86GB of Manchester Airports Group data, exposing 8.7 million customers' personal and booking details.
Manchester Airports Group disclosed a breach on August 27 affecting parking, lounge, Fast Track and WiFi registrations at Manchester, London Stansted and East Midlands airports, impacting 8.7 million customers, most exposed only email addresses. FulcrumSec claims it stole about 86GB via airport-specific Iterable API credentials exposed in client-side JavaScript, including a 21.5GB Manchester export with booking histories, marketing data and nearly 200,000 records on upcoming 2026 travel. BleepingComputer verified sample records against a real traveler's Fast Track history; MAG declined to address the group's specific claims. Researchers warn the combination of UK postcodes, vehicle registrations and booking details could enable convincing targeted phishing, and MAG says no payment card or banking data was exposed.
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused
Rhysida published 5.7 TB of Berlin state government data, including sensitive CBRN emergency plans, after the state refused a €2m ransom demand.
The Rhysida ransomware gang leaked roughly 5.7 TB — about 1.4 million files — stolen from Berlin's state network after the government declined to pay 30 bitcoins (about €2m) by the September 4 deadline. The dump reportedly includes sensitive state emergency plans for terrorist attacks and CBRN disaster scenarios in a folder titled 'AG CBRN-Rahmenplanung', plus personnel files, absence lists, payroll data, and home addresses, potentially affecting tens of thousands of people. Berlin says there are no indications the state network remains compromised and will notify affected individuals on a risk-based basis after forensic analysis.
Details emerge on BlackFile's recent attacks on financial companies
BlackFile (UNC6671), a The Com-linked extortion crew, keeps hitting financial and med tech firms with voice-phishing IT-support scams and ~$3 million demands.
Google Threat Intelligence Group (tracking BlackFile as UNC6671, linked to The Com) reports the extortion group remains active, shifting focus to the financial sector and med tech organizations, with new Redact-brand extortion demands issued last week. The group impersonates IT support in voice-phishing attacks using hundreds of recruited callers, targets large firms in what researchers call big-game hunting, and processes an average of 1.5 new victims daily. Extortion demands start around $3 million and are typically negotiated below $1 million; Flashpoint observed infrastructure targeting Blackstone, Bain Capital, Moody's, CME, and Apollo, though compromise is unconfirmed. Mandiant has responded to more than two dozen BlackFile compromises since January, and victims face escalation tactics including swatting.