Friday, 9 October 2026 SourcesAbout🌓
🇬🇧 UK ▾
BREAKING
› Hunter Bell celebrates in Team GB's 'glam' female track success› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Papers: Fee Man Utd could receive for wantaway JJ Gabriel revealed› Hunter Bell celebrates in Team GB's 'glam' female track success› Chelsea latest: Caicedo features in friendly as midfielder steps up recovery› Swiss Darts Trophy 2026: Schedule, draw, dates as Bunting defends his title› 'It's about time!' - F1 drivers excited amid Rwanda GP rumours› 'Stick together, enjoy the ride and smile' - Haaland's message to Man City fans› Campbell would end retirement to fight Benn: 'He was insulting me!'› Russell, Antonelli to race with different specs amid Mercedes upgrade concern› 'It wasn't good enough' - Hamilton reveals 'huge' talks over Ferrari blunder› Southampton boss Eckert welcomes 'clarity' after Spygate suspended FA ban› Papers: Fee Man Utd could receive for wantaway JJ Gabriel revealed
Technology

ShinyHunters expose 6.4M in attack on medical supplier McKesson

The Register ·
ShinyHunters expose 6.4M in attack on medical supplier McKesson

McKesson's cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP).

The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time.

ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP did not confirm that figure.

The cybercriminals told The Register that they issued a $55.2 million extortion demand to prevent the release of McKesson's data – a sum that apparently was not paid, given the subsequent publication of the data.

HIBP said: "The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff, and healthcare provider contacts." The types of information exposed vary between individuals, but the records collectively include names, email and physical addresses, genders, dates of birth, phone numbers, employer details, and sensitive health information.

This is broadly consistent with ShinyHunters' claims that the stolen data included appointment dates and notes, as well as sensitive medical details such as the locations of patients' cancers.

ShinyHunters also claimed to have stolen Social Security numbers (SSNs) as part of the breach, but HIBP did not include these in its analysis of the leaked corpus.

The Register asked McKesson to comment on HIBP's assessment.

The company, which supports 3,300 oncology providers in 29 states, has not publicly confirmed the scale of the breach or issued further details since the last update from its CIO and CTO on August 29.

Medical device maker Boston Scientific disclosed a cyberattack at around the same time as McKesson, but has suffered a different kind of fallout.

While McKesson is informing the millions of individuals affected by its breach, Boston Scientific told shareholders that disruption from its attack means it expects to miss its sales and earnings guidance for Q3.

An update issued on Wednesday said manufacturing, order fulfillment, and shipping operations had been fully restored, although work to restore some business applications continued.

Healthtech company Veradigm also disclosed a cyberattack to US regulators this week, days after ransomware group The Gentlemen claimed responsibility.

Veradigm said attackers obtained credentials from a third-party vendor's environment and used them to access a company API, stealing patient data without disrupting operations.

Read the full article on The Register ›

5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.

More from The Register

See all ›

More in Technology

See all ›