ShinyHunters claims massive patient data theft from McKesson cloud systems

The hacking group ShinyHunters has claimed responsibility for a cyberattack on pharmaceutical distributor McKesson, saying it stole millions of patient records from cloud-hosted Snowflake and Salesforce environments. The stolen data includes names, addresses, Social Security numbers, and protected health information such as diagnoses and medications, along with employee details. McKesson confirmed the breach and expects service disruptions, while the hackers reportedly demanded a $55 million ransom.
McKesson's breach targeted its oncology and medical-surgical business units, with attackers gaining entry through phishing and social engineering aimed at employees. The stolen data spans cloud-hosted Snowflake and Salesforce systems, containing millions of rows of patient records alongside employee home addresses. The hackers shared sample data with TechCrunch, which verified a small subset against public records.
The incident follows a pattern of recent healthcare attacks, including breaches at Boston Scientific, Stryker, Abbott Laboratories, and Medtronic. ShinyHunters previously claimed responsibility for data thefts at Amazon-owned OneMedical and DentaQuest. McKesson's confirmation noted expected intermittent service degradation as the company responds to the intrusion.
Patients whose records were taken may face heightened risks of identity theft and medical