Skip to main content
McKesson Faces $55M Extortion After 6.4M Records ExposedBreach & Risk Assessment
4 min readFor Data Protection Officers

McKesson Faces $55M Extortion After 6.4M Records Exposed

The Challenge

In August, McKesson faced a serious extortion attack when ShinyHunters, a known cybercriminal group, breached the company's systems and stole what they claimed were 284 million documents. They demanded $55.2 million to keep the data private. McKesson refused to pay, leading ShinyHunters to release the data, exposing records for about 6.4 million individuals, as confirmed by Have I Been Pwned.

The leaked data included information from marketing campaign recipients, patients, staff, and healthcare provider contacts. It contained names, email and physical addresses, genders, dates of birth, phone numbers, employer details, and sensitive health information. ShinyHunters claimed the data included appointment dates, clinical notes, and specific medical details like cancer locations.

The Environment and Constraints

McKesson, a medical and pharmaceutical supply company, supports 3,300 oncology providers across 29 states. This position involves handling complex data flows for patients, providers, and internal operations.

The regulatory environment adds to this complexity. As a healthcare entity, McKesson must comply with HIPAA security and breach notification rules, which require specific safeguards and strict timelines for notifying affected individuals and the Department of Health and Human Services. The breach's scale necessitates prominent media notice and individual notifications.

McKesson's size is both an asset and a liability. Large healthcare organizations handle vast amounts of sensitive data across distributed systems, creating a broad attack surface. ShinyHunters targeted these data aggregation points where patient, provider, and operational information converge.

The Approach Taken

McKesson's public response has been cautious. The CIO and CTO issued an update on August 29, but the company hasn't confirmed the breach's scale or provided detailed incident analysis since. This silence leaves a gap between what Have I Been Pwned confirmed and what McKesson has disclosed.

The decision not to pay the $55.2 million demand aligns with guidance from the FBI and CISA, which advise against paying ransoms, as it doesn't guarantee Data Purging and funds criminal activities. However, refusing payment means managing the consequences of the data being published.

McKesson is now notifying the 6.4 million affected individuals. Each notification must be tailored to the specific data types exposed, comply with HIPAA's content requirements, and be delivered through appropriate channels.

Results and Metrics

The breach exposed 6.4 million individual records, as verified by Have I Been Pwned. ShinyHunters published the data after their extortion demand was declined, making it accessible to other threat actors.

ShinyHunters' approach suggests they targeted document repositories rather than just structured databases. This method captures clinical notes, appointment records, and unstructured health information that often contain more sensitive details.

McKesson's operations remain unaffected. Unlike Boston Scientific, which reported a cyberattack and expects to miss Q3 sales and earnings guidance, McKesson hasn't reported operational disruptions. This indicates the attack focused on data exfiltration rather than system disruption.

Lessons for Improvement

While McKesson hasn't shared a lessons-learned analysis, the incident highlights areas for improvement that other healthcare organizations should consider.

The lack of early detection is significant. Exfiltrating 284 million documents requires sustained access and significant data transfer. Organizations with strong data loss prevention and network monitoring should detect unusual outbound traffic patterns during extraction. McKesson's timeline suggests the attackers had ample time to catalog and extract large document volumes.

Veradigm's breach, disclosed the same week, offers a contrasting scenario. Attackers used credentials from a third-party vendor to access a Veradigm API, stealing patient data without operational disruption. This highlights a vulnerability: API access controls relying solely on credentials create a clear path for attackers who compromise vendor environments.

Third-party credential compromise is a high-value attack vector. Organizations need API authentication that goes beyond credentials, including contextual verification and rate limiting.

Takeaways for Your Team

Implement data-aware monitoring. Establish baselines for document access patterns, API call volumes, and outbound transfer sizes. Alert on deviations to detect exfiltration.

Strengthen API authentication. Don't rely solely on credentials for third-party APIs. Use certificate-based authentication, IP allowlisting, and enforce rate limits to prevent mass data extraction.

Segment by data sensitivity. Different data types require different protection levels. Apply measures proportionate to data sensitivity; marketing contacts don't need the same controls as clinical records.

Prepare for non-payment scenarios. Have a response plan ready for extortion demands. This includes notification templates, legal counsel, and communication protocols. McKesson's decision not to pay required operational readiness.

Test breach notification at scale. Automate notification generation, delivery tracking, and response management. Test your system with realistic volumes before an incident occurs.

Verify vendor security posture. Ensure vendors demonstrate strong credential management, enforce multi-factor authentication, and limit API access to specific IP ranges.

ShinyHunters exploited gaps in a complex environment. Your team's job is to close those gaps before the next attack.

You Might Also Like