Loading Curie Briefs...
Getting the latest healthcare news for you
Getting the latest healthcare news for you

Healthcare giant McKesson confirmed that hackers accessed and stole data from its third-party applications, affecting customers in its oncology and medical-surgical businesses. The hacking group ShinyHunters is claiming responsibility, alleging it obtained over 284 million patient records and demanding ~$55 million in ransom. McKesson says its distribution network remains operational, but the full scope of the breach is still unknown.
Healthcare distributor McKesson confirmed that an unauthorized party accessed its third-party applications and exfiltrated data belonging to a subset of customers in its oncology, multispecialty, and medical-surgical business units. The company discovered the incident on August 25 and has since activated incident response protocols, engaged cybersecurity experts, and filed a disclosure with the SEC. McKesson says it has "reasonable assurance" of no ongoing unauthorized activity, and its distribution network — which makes roughly 40,000 deliveries daily to care sites nationwide — remains operational.
The hacking group ShinyHunters has claimed responsibility, alleging it used voice phishing to compromise employee accounts and access cloud applications. The group claims to have stolen over 284 million patient records — including names, Social Security numbers, patient IDs, prescription data, and billing records — and is reportedly demanding ~$55 million to withhold the files. McKesson has not confirmed these claims, and the number of people affected remains unknown.
By the Numbers:
Why it matters: McKesson is a logistical backbone of the U.S. healthcare system, making this breach a significant systemic risk. The attack method — voice phishing to hijack employee accounts — is increasingly common and hard to detect, underscoring the urgent need for stronger identity verification across healthcare organizations.