Close Menu

    Stay Ahead with Exclusive Updates!

    Enter your email below and be the first to know what’s happening in the ever-evolving world of technology!

    What's Hot

    Stripe Acquires OpenRouter in $7.5B AI Infrastructure Deal

    September 12, 2026

    Emerald AI Secures $150M to Halt Data Center Grid Crisis

    September 12, 2026

    Pentagon Adds ChatGPT and Grok; Leaves Claude Locked Out

    September 12, 2026
    Facebook X (Twitter) Instagram
    Facebook X (Twitter)
    PhronewsPhronews
    • Home
    • Big Tech & Startups

      Stripe Acquires OpenRouter in $7.5B AI Infrastructure Deal

      September 12, 2026

      Emerald AI Secures $150M to Halt Data Center Grid Crisis

      September 12, 2026

      Pentagon Adds ChatGPT and Grok; Leaves Claude Locked Out

      September 12, 2026

      FTC Sues Amazon Over Secret Ad Pricing Algorithm Scheme

      September 12, 2026

      Is Anthropic’s $35B Nvidia Compute Deal an Antitrust Risk?

      September 12, 2026
    • Crypto

      A Firmware Flaw in One of the Most Trusted Bitcoin Hardware Wallets Just Drained Over $70 Million in Crypto. The Coldcard Breach Is a Reminder That Cold Storage Is Only as Safe as the Code Running Inside It

      August 29, 2026

      Market Collapse: What Happened to NFTs?

      April 23, 2026

      Quantum Computing Advances Force Coinbase and Institutional Custodians to Rethink Crypto Security

      March 8, 2026

      AI Assisted Hacking Groups Target Crypto Firms With Multi-Layered Social Engineering

      February 18, 2026

      Global Crypto Regulations Expand as 2026 Begins With New Data Collection Frameworks and National Laws

      January 16, 2026
    • Gadgets & Smart Tech
      Featured

      Chinese Humanoid Robots Just Ran 100 Metres Faster Than Usain Bolt. The Record Nobody Thought Would Fall to a Machine Just Did.

      By preciousSeptember 5, 2026
      Recent

      Chinese Humanoid Robots Just Ran 100 Metres Faster Than Usain Bolt. The Record Nobody Thought Would Fall to a Machine Just Did.

      September 5, 2026

      Meta Found a Zero-Click iPhone Vulnerability That Let Hackers Into Devices Without the Owner Doing Anything. Apple Patched It. The Fact That Meta Found It First Is the Uncomfortable Part.

      September 2, 2026

      Google Has Launched the Pixel 11 With Its New Tensor G6 Chip and the Deepest Gemini Integration Any Android Phone Has Ever Shipped With. Here Is Whether the Hardware Finally Matches the AI Ambition.

      August 25, 2026
    • Cybersecurity & Online Safety

      McKesson Hit by $55M Ransom Demand Over Huge Patient Breach

      September 12, 2026

      Microsoft 365 Outage Exposes Enterprise AI Vulnerabilities

      September 11, 2026

      No Explosives Needed: How Iranian Hackers Darkened a UK Power Plant for 96 Hours

      September 9, 2026

      Meta Found a Zero-Click iPhone Vulnerability That Let Hackers Into Devices Without the Owner Doing Anything. Apple Patched It. The Fact That Meta Found It First Is the Uncomfortable Part.

      September 2, 2026

      A Supply Chain Attack on LiteLLM Exposed 153GB of Corporate Cloud Keys. The Breach Hit the Layer of AI Infrastructure That Almost Nobody Was Watching.

      September 1, 2026
    PhronewsPhronews
    Home»Cybersecurity & Online Safety»McKesson Hit by $55M Ransom Demand Over Huge Patient Breach
    Cybersecurity & Online Safety

    McKesson Hit by $55M Ransom Demand Over Huge Patient Breach

    fariehanBy fariehanSeptember 12, 2026No Comments
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email
    Photo Credit: IgorGolovniov via Shutterstock

    McKesson, a major healthcare distributor, faces a $55.2 million ransom claim from the ShinyHunters extortion group. On the 25th of August, the company discovered the incident and disclosed it in an SEC filing. 

    The investigation remains in the early stages. The company has not determined whether the incident will materially affect finances or operations. Nevertheless, the case raises concern because the company supports critical healthcare supply chains.

    What Happened

    McKesson reported unauthorized access to certain third-party applications and the exfiltration of certain data. The company linked the incident to customer subsets in its Oncology & Multispecialty and Medical-Surgical business units.

    Meanwhile, ShinyHunters added the company to its leak site and claimed responsibility. The group says it took roughly 284 million customer records. It claims the data includes personal, health, prescription, billing, employee, physician, and clinic information.

    However, McKesson has not confirmed the number of people affected or the data types involved. The company continues to investigate what attackers may have accessed or acquired.

    McKesson says it disrupted the unauthorized activity after discovering the incident. It also says it has reasonable assurance that no unauthorized activity continues and distribution centers remain open, and customers can continue using its systems and services.

    How Attackers Got In

    ShinyHunters claims it used voice phishing, or vishing, against two employees. The group says it then accessed Salesforce and Snowflake environments. McKesson has not verified the alleged attack path.

    Still, the claim matches a broader campaign that has been tracked. Attackers use voice-based social engineering, credential phishing, and device-code phishing to access corporate data. They often pose as technical-support staff during phone calls.

    In addition, attackers can convince users to approve malicious applications through trusted sign-in pages. Those applications can then access data within the user’s account permissions. As a result, a single deceptive call can bypass expected security checks.

    The McKesson Breach: The Stakes

    McKesson distributes medicines and medical supplies to hospitals, pharmacies, clinics, biopharma companies, manufacturers, and government customers. In addition, the company distributes roughly one-third of prescription medicines to North American healthcare organizations.

    Therefore, a confirmed data breach could affect more than one organization. Criminals could use identity information for fraud and targeted scams. They could also use health information to pressure victims or conduct further phishing.

    Also, federal privacy rules add another layer of risk. HHS requires covered entities to notify affected individuals after qualifying breaches of unsecured protected health information. Organizations must issue those notices without unreasonable delay and within 60 days.

    Large breaches can also require reports to HHS and notices to local media outlets. Consequently, the confirmed scope and data types will shape the company’s legal response.

    What Comes Next

    Currently, McKesson says it has activated incident-response protocols and engaged cybersecurity experts. It continues to monitor its environment while investigators assess the breach.

    The company must determine what attackers accessed, who may face risk, and whether notification rules apply. Those findings will guide any customer and patient communications.

    For now, readers should follow official updates, regulatory filings, and direct notifications. Until investigators verify the claims, ShinyHunters’ ransom demand and record total remain unconfirmed.

    breach investigation CyberAttack Cybercrime cybersecurity cybersecurity threat Data Breach data theft Healthcare Cybersecurity healthcare data healthcare supply chain McKesson McKesson breach phishing Ransomware ShinyHunters Vishing voice phishing
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email
    fariehan

    Related Posts

    Microsoft 365 Outage Exposes Enterprise AI Vulnerabilities

    September 11, 2026

    Hackers Trick Cursor AI Agent into Breaching 20 Companies

    September 10, 2026

    No Explosives Needed: How Iranian Hackers Darkened a UK Power Plant for 96 Hours

    September 9, 2026

    Comments are closed.

    Top Posts

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025

    MIT Study Reveals ChatGPT Impairs Brain Activity & Thinking

    June 29, 2025
    Don't Miss
    Artificial Intelligence & The Future

    Stripe Acquires OpenRouter in $7.5B AI Infrastructure Deal

    By preciousSeptember 12, 2026

    As companies build AI products with a growing mix of models, choosing which system should…

    Emerald AI Secures $150M to Halt Data Center Grid Crisis

    September 12, 2026

    Pentagon Adds ChatGPT and Grok; Leaves Claude Locked Out

    September 12, 2026

    FTC Sues Amazon Over Secret Ad Pricing Algorithm Scheme

    September 12, 2026
    Stay In Touch
    • Facebook
    • Twitter
    About Us
    About Us

    Evolving from Phronesis News, Phronews brings deep insight and smart analysis to the world of technology. Stay informed, stay ahead, and navigate tech with wisdom.
    We're accepting new partnerships right now.

    Email Us: info@phronews.com

    Facebook X (Twitter) Pinterest YouTube
    Our Picks
    Most Popular

    Coinbase responds to hack: customer impact and official statement

    May 22, 2025

    Cursor AI Hits 1 Million Daily Users. Why Developers Are Switching to This Coding Tool

    March 23, 2026

    Anthropic Will Use Claude User Chats For Data Training

    October 16, 2025
    © 2025. Phronews.
    • Home
    • About Us
    • Get In Touch
    • Privacy Policy
    • Terms and Conditions

    Type above and press Enter to search. Press Esc to cancel.