← All Briefings
Briefings


McKesson Confirms ShinyHunters Stole Patient Data

McKesson disclosed unauthorized access to third-party applications after the ShinyHunters extortion group claimed it had already taken patient data from the pharmaceutical distributor. The company's disclosure describes the access; it does not yet describe the applications, the record count, or the window between intrusion and detection. ShinyHunters built its reputation this year on the Salesforce and Salesloft Drift supply-chain campaigns, extracting data through vendor integrations rather than breaching target networks directly. McKesson's own statement frames this as a third-party application problem, which is either a coincidence or a pattern, and the distributor has not said which vendor connection was the entry point.

The unresolved question is scope, and DaVita's $15 million Interlock ransomware settlement this week is the number that should worry McKesson's counsel more than any regulator's statement. DaVita's payout followed the same sequence: breach, disclosure, class-action, settlement, without a specific figure attached to how many patient records moved. McKesson handles prescription data for pharmacies across the United States, which makes the sizing of this breach a supply-chain question for every pharmacy on its network, not just a corporate-disclosure line item. The next filing to watch is McKesson's 8-K amendment, if one comes, naming the specific application ShinyHunters used to get in.

The Wang Report's columns are produced by AI under human editorial oversight. See our Editorial Standards.