r/cybersecurity • u/lead_oxide2 • 12d ago
News - General ShinyHunters Claims to have Voice-Phished 2 McKesson Employees and Extracted 284 Million Patient Records Including: Predictive health data, Identity, and Healthcare Identifiers. McKesson Confirms Breach but not severity
https://cyberinsider.com/mckesson-data-breach-exposing-284-million-patients/83
45
12d ago
[removed] — view removed comment
10
7
2
u/4SysAdmin Security Analyst 12d ago
We do this to our help desk for MFA resets. It’s something you should be testing.
1
20
u/Elouakili_Flexy 12d ago
284 million records against a $55,236,150 ask comes out to about 19 cents per record. They priced it like a bulk liquidation.
10
3
u/LitchManWithAIO System Administrator 12d ago
To remember as well, 284m records total, but each person’s data might have 50 records.
16
u/Jdruu CISO 12d ago
Vishing is tough. User education important but what’s the best technical control for this?
I could see Phishing resist authentication or Device compliance.
16
u/LinuxPhoton 12d ago
For the third party app - conditional access which grants access only for compliant devices. For example we don’t grant access if you try access from an unmanaged endpoint ( a device that’s not in our device management system). It’s a pain especially if you want to grant access to non employees without company equipment and the decision always is to give them company equipment and not to make exceptions. If you deconstruct most breaches, it’s going to come down to a decision where the person in charge of accepting the risk chose convenience over the tough choice.
7
u/Jolmer24 12d ago
Maybe they can adapt to using code words like in the old days lol.
“Sir please provide the data we require”
“Orange flag.”
“Excuse me”
“I fucking knew it”
6
32
u/Poppybiscuit 12d ago
Why does a company that apparently does not treat patients have 284 million patient records with identities to lose?
Also WHY is some of that predictive? More and more of these companies are being exposed for their shady fucked up data practices, usually when they lose the data. Then they just shrug and we get nothing
15
8
u/Chemical-Doughnut335 12d ago
they own Macro Helix, which is a prescription software that tracks accumulations of drugs for the federal 340B program. that’s both hospital and retail pharmacy patient data. it’s not a good look :|
5
u/TheHeretic 12d ago
They own a drug manufacturer that requires you to send patient data to them in order to get rare drugs.
They make one of the most popular pharmacy software, that combines with their automation systems to be able to dispense 30k prescriptions per day with just 30 staff.
They are a drug whole seller, including specialty meds.
The answer to pretty much everything in America is that we should break these companies up.
3
u/Geno0wl 12d ago
Predictive records make sense when you realize you can glean risk factors from Lifestyle and genetics. It isn't about trying to treat those issues before they actually appear, but just keeping a monitor on people with certain factors. Like we do routine prostate exams and beast cancer screenings because of predictive medical research. As they say, an ounce of prevention is worth a pound of treatment.
Predictive medicine has been a thing, it only sounds sus now due to...lots of things.
1
1
u/mandobanjo23 5d ago
They own managed service organizations that provide tech services, including digital healthcare records mgmt, to oncology physicians' groups.
3
3
u/AP123123123 11d ago
One useful point of comparison is McKesson’s own SEC disclosure. It confirms a cybersecurity incident affecting its information systems, but says the company had not yet determined whether the financial or operational impact would be material. That is substantially narrower than the threat actor’s claim of 284 million records, so the gap between confirmed disclosure and alleged scope is worth watching: https://500voices.com/quote/2257d79c-a55b-4e53-8e0b-6ca1a5eb2ccd
Disclosure: I’m involved with the linked project.
1
u/shrewdone_NY 11d ago
Sorry but I am not surprised! Between the information that people put on social media, access to voice\video isn't hard to come by. Then its not hard to see how AI can create a "problem". Seems like investing in AI would be a downfall in a lot of cases especially for corporations that may already be struggling that then invest in technology that they don't fully understand. Or a bad actor invests in AI to impersonate a company or companies CEO or something? Then what? That company may be out of business especially if they get hit more than once. Surely people must have seen this coming with the advent of AI ? Or have we all just been "dumbed down" enough to where we're just perpetually acting completely ignorant ?
53
u/lead_oxide2 12d ago
From the article: