Healthcare Giant McKesson Grapples with Cyberattack, Data Exfiltration Confirmed
Pharmaceutical and healthcare technology giant **McKesson** is currently investigating a cybersecurity incident that has led to intermittent service disruptions and confirmed data exfiltration. The attack, claimed by the notorious cybercriminal group **ShinyHunters**, targeted a third-party application, impacting customer data within **McKesson**'s oncology and surgical business units.
# Healthcare Giant McKesson Grapples with Cyberattack, Data Exfiltration Confirmed
**McKesson**, a leading pharmaceutical and healthcare technology company, has disclosed a cybersecurity incident causing service degradation and confirming data exfiltration. The company, which handles approximately one-third of all prescriptions in North America, released a public notice and filed documents with the **Securities and Exchange Commission (SEC)** on Friday evening.
## Third-Party Application Compromised
According to **McKesson** Chief Technology Officer **Francisco Fraga**, the incident originated from a compromised unnamed third-party application. Attackers gained unauthorized access to this application, subsequently exfiltrating data.
"At this time, customers may experience intermittent service degradation that we believe may be related to this incident," Fraga stated. "We are aware of these issues and continue to monitor the situation closely."
## Data Exfiltration and Customer Impact
An update on Saturday confirmed that the hackers successfully exfiltrated data associated with customers in **McKesson**'s oncology and surgical business units. In response, **McKesson** plans to provide credit monitoring and identity protection services to affected customers.
While the investigation is ongoing, **McKesson** has received "reasonable assurance" that the attackers are no longer present within their systems. Fraga emphasized that customers can continue to utilize their systems and services as intended, noting that the company has not proactively disconnected systems β a measure often taken during ransomware attacks to contain the spread.
Customers experiencing technical issues are urged to contact the company directly. **McKesson** has not provided further details on the incident as the investigation progresses.
## ShinyHunters Claims Responsibility
The prominent cybercriminal group **ShinyHunters** has claimed responsibility for the attack, threatening potential data leaks on their blog. This group has a history of targeting and extorting major corporations globally over the past two years.
Earlier this year, the **FBI** issued a warning regarding hackers linked to **ShinyHunters**, who were demanding substantial ransom payments after stealing data through compromises involving **Salesforce** environments. The group has been implicated in several high-profile incidents, including an attack on a widely used educational software suite in May and the theft of information from over four million individuals from a major medical device company in April.
Past victims of **ShinyHunters** include **Carnival Cruises**, **Ticketmaster**, **AT&T**, **McGraw Hill**, **ADT**, and gaming company **Rockstar**.
## Healthcare Sector Under Siege
**McKesson**'s incident marks another significant cyberattack within the healthcare sector this year. Other major healthcare companies, including medical device giants **Boston Scientific**, **Medtronic**, and **Stryker**, have also reported cybersecurity incidents recently, highlighting a persistent and growing threat to critical healthcare infrastructure.
**McKesson**, which reported $106 billion in revenue last quarter, plays a crucial role in distributing pharmaceuticals, producing oncology drugs, and manufacturing essential medical-surgical supplies and laboratory equipment.