ZeroHour
Story · 1 source · 1 articlefirst updated ()

Veradigm API breach and ShinyHunters' 6.4M-record McKesson leak widen healthcare attack wave

highData breachexploited in the wildimportance 78
What's new: New developments as of 2026-09-09/10: Veradigm publicly disclosed the vendor-credential API breach via an SEC 8-K, and the Gentlemen gang listed Veradigm on its leak site with a claimed 3.5 million patient records. HIBP ingested ShinyHunters' leaked McKesson data on 2026-09-10, confirming ~6.4 million affected individuals and revealing the true scale of the August 2026 attack after ShinyHunters'…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

Veradigm disclosed that attackers used stolen vendor credentials to access an API and take patient data including SSNs, with the Gentlemen gang claiming 3.5 million patient records, while HIBP data confirmed ShinyHunters' August 2026 attack on McKesson…

Electronic health records company Veradigm filed an 8-K with the SEC stating that an unauthorized party obtained credentials from a vendor's environment and used them to access a Veradigm API, downloading patients' personal data including Social Security numbers. Veradigm said no clinical or medical data was involved, access was limited to the specific API interface, and there was no operational disruption. The Gentlemen ransomware gang added Veradigm to its leak site claiming the theft of 3.5 million patients' health records; the reports attribute that figure to the gang's claim rather than Veradigm's filing. Separately, Have I Been Pwned added data leaked by the extortion group ShinyHunters from medical and pharmaceutical supplier McKesson, confirming that the August 2026 attack affected roughly 6.4 million individuals - the first public indication of the attack's true scale. Exposed data includes names, email and physical addresses, dates of birth, phone numbers, employer details, and sensitive health information. ShinyHunters claimed it stole SSNs and 284 million documents and issued a $55.2 million extortion demand that was apparently unpaid before publication; sources disagree on SSNs, as HIBP found none in the leaked data. The incidents sit within a broader healthcare breach wave: Veradigm was previously hit by SamSam ransomware in 2019 and disclosed a December 2024 breach affecting 2,672,036 people, Boston Scientific expects to miss Q3 sales and earnings guidance after its own cyberattack, and other reported incidents include Aesto (~9 million), CareCloud (~3.7 million), and Baylor Genetics (~2.8 million).

  • Veradigm filed an 8-K with the SEC disclosing that an unauthorized party obtained credentials from a vendor's environment and used them to access a Veradigm API, downloading patient personal data including Social Security numbers.
  • Veradigm says no clinical or medical data was involved, access was limited to the specific API interface, and there was no operational disruption.
  • The Gentlemen ransomware gang added Veradigm to its leak site claiming theft of 3.5 million patients' health records; the count comes from the gang's claim.
  • Veradigm was previously hit by SamSam ransomware in 2019 and disclosed a December 2024 breach affecting 2,672,036 people; the company serves thousands of hospitals and doctors and reported $594M revenue in 2024.
  • Have I Been Pwned added ShinyHunters-leaked McKesson data, confirming the August 2026 attack affected roughly 6.4 million individuals - the first public indication of the attack's scale.
  • McKesson exposed data includes names, email and physical addresses, dates of birth, phone numbers, employer details, and sensitive health information.
  • ShinyHunters claimed 284 million documents and SSNs were stolen from McKesson and demanded $55.2 million; the demand was apparently unpaid and the data was published. Sources disagree on SSNs: HIBP found none in the leaked data.
  • Boston Scientific expects to miss Q3 sales and earnings guidance following its own separate cyberattack.

Coverage timeline

  1. · 7d ago
    The Record· 78
    Electronic health record company says customer data stolen in breach

    Veradigm disclosed that attackers used stolen vendor credentials via an API to steal patient data including Social Security numbers, as the Gentlemen ransomware gang claims 3.5 million patients' records.