Skip to main content
Emerging ThreatsData Breaches

ShinyHunters Breach Exposes 6.4M in McKesson Cyberattack

Hospital corridor with people walking and sitting, medical devices in background.

"The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff, and healthcare provider contacts." — Have I Been Pwned (HIBP)

Have I Been Pwned: 6.4 million individuals identified

Have I Been Pwned (HIBP) published an assessment this week that places the scale of the McKesson incident at roughly 6.4 million affected individuals. That figure comes from HIBP's analysis of data leaked by the extortion group ShinyHunters and represents the first public estimate of the number of people whose records appeared in the published corpus.

What types of information appeared in the leaked corpus

According to HIBP, the exposed records vary by individual but collectively include names, email and physical addresses, gender, dates of birth, phone numbers, employer details, and sensitive health information. HIBP's characterization aligns broadly with ShinyHunters' claims that the theft included appointment dates and notes and specific medical details — the extortionists asserted the data contained such items as locations of patients' cancers.

ShinyHunters also claimed to have stolen Social Security numbers (SSNs) as part of the breach; HIBP's analysis, however, did not include SSNs in the leaked corpus it examined.

ShinyHunters' claims and the extortion demand

ShinyHunters first claimed in August to have taken 284 million documents from McKesson. The group told The Register it issued a $55.2 million extortion demand to prevent release of the files. The subsequent publication of data indicates the ransom demand was not paid.

McKesson's posture and its oncology network

McKesson has not publicly confirmed the full scale of the breach or provided additional detail since an update from its CIO and CTO on August 29. The company supports 3,300 oncology providers in 29 states — a fact that underscores the potential breadth of clinical contacts and patients connected to McKesson's services.

While McKesson itself has remained limited in public comment since the late-August update, HIBP reports that McKesson is informing the millions of individuals affected by the breach.

Parallel incidents: Boston Scientific and Veradigm

The McKesson disclosure comes amid separate, contemporaneous incidents affecting other healthcare and health-technology companies. Medical device maker Boston Scientific disclosed a cyberattack at around the same time; its public disclosures to shareholders said the disruption would lead it to miss sales and earnings guidance for the third quarter. Boston Scientific later reported manufacturing, order fulfillment, and shipping operations had been fully restored, with work on some business applications still ongoing.

Healthtech company Veradigm also disclosed a cyberattack to U.S. regulators after ransomware group The Gentlemen claimed responsibility. Veradigm said attackers obtained credentials from a third-party vendor environment and used them to access a company API, stealing patient data without disrupting operations. The Gentlemen claimed to have taken roughly 3.5 million records containing personally identifiable information, including SSNs.

What this means for patients, oncology providers, and security teams

  • Patients and individuals named in the leak: HIBP's analysis indicates millions have some form of personal and sensitive health data exposed. McKesson is notifying affected individuals, according to HIBP, but the presence of sensitive clinical details in the published corpus raises risks of privacy harm and potential exploitation for secondary fraud.
  • Oncology providers that rely on McKesson: With McKesson supporting 3,300 oncology providers in 29 states, providers are likely to be tracking incident status and communications closely; the presence of appointment notes, dates, and clinical specifics in the leak can affect provider-patient confidentiality and clinical workflows.
  • Security teams and third-party vendors: The Veradigm incident highlights credential theft from a third-party vendor as a vector. Security teams supporting healthcare firms and vendors will be watching whether stolen credentials or API access are recurring patterns across these contemporaneous intrusions.

The record published by ShinyHunters and HIBP's subsequent tally leave two clear facts in view: a public estimate of roughly 6.4 million affected individuals, and an unresolved discrepancy over the presence of SSNs — claimed by the extortionists but not included in HIBP's analysis. McKesson's limited public commentary since August 29 and the $55.2 million extortion demand reported by ShinyHunters frame the incident as both a significant data exposure and an episode in an ongoing pattern of healthcare-related cyber intrusions. Observers and those affected will be watching for further public confirmation from McKesson and any regulator filings that detail the scope and content of the records that were leaked.

Source: The Register — ShinyHunters expose 6.4M in attack on medical supplier McKesson