Loading Curie Briefs...
Getting the latest healthcare news for you
Getting the latest healthcare news for you

Healthcare giant McKesson confirmed a cybersecurity breach tied to third-party applications, with hackers claiming to have stolen data on over 284 million patients. The extortion group ShinyHunters is demanding $55 million to keep the files private. McKesson says operations remain unaffected and is offering credit monitoring and identity protection to impacted individuals.
Healthcare distribution giant McKesson Corporation confirmed it is investigating a cybersecurity incident discovered on August 25, after hackers gained unauthorized access to data through third-party applications. The company activated incident response protocols and engaged external cybersecurity experts, and reports "reasonable assurance" of no ongoing unauthorized activity in its systems.
The notorious cyber extortion group ShinyHunters claims to have stolen data on over 284 million patients, including names, home addresses, Social Security numbers, patient IDs, prescription records, predictive health data, and billing information — primarily from McKesson's Oncology & Multispecialty and Medical-Surgical business units. The group is demanding approximately $55 million to prevent public release of the files.
McKesson says its distribution centers remain operational and it continues to serve customers across all business lines. The company is offering complimentary credit monitoring and identity protection services to affected individuals.
By the Numbers:
Why it matters: If confirmed at scale, this could be one of the largest healthcare data breaches in U.S. history, raising urgent questions about third-party vendor security and the vulnerability of critical healthcare supply chain infrastructure.