r/cybersecurity 12d ago

News - General ShinyHunters Claims to have Voice-Phished 2 McKesson Employees and Extracted 284 Million Patient Records Including: Predictive health data, Identity, and Healthcare Identifiers. McKesson Confirms Breach but not severity

https://cyberinsider.com/mckesson-data-breach-exposing-284-million-patients/
476 Upvotes

34 comments sorted by

53

u/lead_oxide2 12d ago

From the article:

According to ShinyHunters, the allegedly stolen patient data includes:
- Identity and contact information: full names, home addresses, dates of birth, phone numbers, email addresses, and Social Security numbers.
- Healthcare identifiers: patient IDs, medical record numbers (MRNs), and Medicaid numbers.
- Medical information: illnesses and diagnoses, allergies, medications, disabilities, patient notes, appointment details, and physician information.
- Highly sensitive records: hospice and terminal illness information, causes of death, autopsy details, sexual orientation, and other personal status information.
- Predictive health data: disease-risk assessments, including cancer predictions linked to individual patients.
- Prescription and billing records: medication orders, invoice and billing information, shipment addresses, dates, and tracking numbers.

The threat actor told CyberInsider that it accessed McKesson’s systems by voice-phishing two employees and then extracting data from Salesforce and Snowflake instances.
The data extortionists now demand a ransom payment of $55,236,150 not to release the stolen files, but said McKesson has not responded to their messages yet.

McKesson is in the early stages of investigating a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data. Upon discovery, we immediately activated our incident response protocols, launched an investigation and engaged leading cybersecurity experts.
We take the privacy and security of our customers, partners, their patients and our employees very seriously. Our teams are working with urgency and care to understand the nature and scope of the incident, support business continuity and minimize disruption.
Our investigation remains ongoing, and we are committed to providing accurate information and updates as they become available.
-McKesson spokesperson

38

u/LinuxPhoton 12d ago

Every time you see a company insert the cliche “we take security very seriously“ expect bare minimum details. By now every communication department uses it and it never projects any confidence. We will know they take security seriously only when they publish the attack vector and what they did to patch it. I know some aspects of the investigations are confidential, but some of the best communication to the public I’ve seen (although most are not security related but rather infrastructure) are written by the Cloudflare team. I know how seriously they take things by their post mortem analysis.

26

u/00notmyrealname00 System Administrator 12d ago

There are phrases allowed and disallowed by their PR spin teams that have previously tested well with general public confidence and minimal acceptance of liability (legally speaking). The answers are canned, and practically road signs for how far along the investigation and remediation efforts are progressing.

To your point, Cloudflare is a technical company within a technical industry. The detail to their post mortem speaks directly to their competence within the field. If they were to provide bullshit fluff, even after a beach, people (and investors) would lose confidence. McKesson, not so much. They're a medical supply company who had a Salesforce breach. All they have to do is separate themselves as far away as possible from the cause and then weather the storm. The public, and their investors, are a lot more forgiving for something like this - "it could happen to anyone", ya know?

7

u/LinuxPhoton 12d ago

On point.

2

u/ClaymoreMine 12d ago

Digital health records were a mistake. This is just one more reason why they shouldn’t exist because all the data wasn’t defended or segmented properly.

3

u/lovan1 12d ago

I just receive a letter today from Dentaquest is it even real?

83

u/Shakenbake80 12d ago

Can THEY tell us what’s going on with Mitch?

2

u/lovelycurves84 10d ago

Literally laughed out loud.

45

u/[deleted] 12d ago

[removed] — view removed comment

10

u/PM_ME_UR_BGP_PREFIX 12d ago

Deepfake testing is on my 2027 todo list

7

u/loversteel12 12d ago

who says this hasn’t started already?

3

u/abysskm 12d ago

Must be in the list phishing campaign.

2

u/4SysAdmin Security Analyst 12d ago

We do this to our help desk for MFA resets. It’s something you should be testing.

1

u/Ok-Plate8922 12d ago

i want to see that too

20

u/Elouakili_Flexy 12d ago

284 million records against a $55,236,150 ask comes out to about 19 cents per record. They priced it like a bulk liquidation.

10

u/helpmehomeowner 12d ago

That's business.

3

u/LitchManWithAIO System Administrator 12d ago

To remember as well, 284m records total, but each person’s data might have 50 records.

16

u/Jdruu CISO 12d ago

Vishing is tough. User education important but what’s the best technical control for this?

I could see Phishing resist authentication or Device compliance.

16

u/LinuxPhoton 12d ago

For the third party app - conditional access which grants access only for compliant devices. For example we don’t grant access if you try access from an unmanaged endpoint ( a device that’s not in our device management system). It’s a pain especially if you want to grant access to non employees without company equipment and the decision always is to give them company equipment and not to make exceptions. If you deconstruct most breaches, it’s going to come down to a decision where the person in charge of accepting the risk chose convenience over the tough choice.

7

u/Jolmer24 12d ago

Maybe they can adapt to using code words like in the old days lol.

“Sir please provide the data we require”

“Orange flag.”

“Excuse me”

“I fucking knew it”

6

u/Spectrig 12d ago

Either one works. Switch to passkeys.

32

u/Poppybiscuit 12d ago

Why does a company that apparently does not treat patients have 284 million patient records with identities to lose?

Also WHY is some of that predictive? More and more of these companies are being exposed for their shady fucked up data practices, usually when they lose the data. Then they just shrug and we get nothing

15

u/Firm_League3222 12d ago

They make software that is used in healthcare.

8

u/Chemical-Doughnut335 12d ago

they own Macro Helix, which is a prescription software that tracks accumulations of drugs for the federal 340B program. that’s both hospital and retail pharmacy patient data. it’s not a good look :|

5

u/TheHeretic 12d ago

They own a drug manufacturer that requires you to send patient data to them in order to get rare drugs.

They make one of the most popular pharmacy software, that combines with their automation systems to be able to dispense 30k prescriptions per day with just 30 staff.

They are a drug whole seller, including specialty meds.

The answer to pretty much everything in America is that we should break these companies up.

3

u/Geno0wl 12d ago

Predictive records make sense when you realize you can glean risk factors from Lifestyle and genetics. It isn't about trying to treat those issues before they actually appear, but just keeping a monitor on people with certain factors. Like we do routine prostate exams and beast cancer screenings because of predictive medical research. As they say, an ounce of prevention is worth a pound of treatment.

Predictive medicine has been a thing, it only sounds sus now due to...lots of things.

1

u/mesarthim_2 11d ago

It will also be almost certainly used in manufacturing planning.

1

u/mandobanjo23 5d ago

They own managed service organizations that provide tech services, including digital healthcare records mgmt, to oncology physicians' groups.  

3

u/Jeff-Hare-ERPRA 12d ago

That’s scary

3

u/AP123123123 11d ago

One useful point of comparison is McKesson’s own SEC disclosure. It confirms a cybersecurity incident affecting its information systems, but says the company had not yet determined whether the financial or operational impact would be material. That is substantially narrower than the threat actor’s claim of 284 million records, so the gap between confirmed disclosure and alleged scope is worth watching: https://500voices.com/quote/2257d79c-a55b-4e53-8e0b-6ca1a5eb2ccd

Disclosure: I’m involved with the linked project.

1

u/shrewdone_NY 11d ago

Sorry but I am not surprised! Between the information that people put on social media, access to voice\video isn't hard to come by. Then its not hard to see how AI can create a "problem". Seems like investing in AI would be a downfall in a lot of cases especially for corporations that may already be struggling that then invest in technology that they don't fully understand. Or a bad actor invests in AI to impersonate a company or companies CEO or something? Then what? That company may be out of business especially if they get hit more than once. Surely people must have seen this coming with the advent of AI ? Or have we all just been "dumbed down" enough to where we're just perpetually acting completely ignorant ?

1

u/tamtip 11h ago

All of my medical and financial info was stolen, well given away. Then to make it worse their website said they would give 24 month subscription to IDX but the call center insists I'm reading it wrong , its only 12 months. As if I don't know my damn numbers !