Data BreachBleeping Computer
8.5 — CRITICAL
McKesson discloses breach after ShinyHunters claims patient data theft
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
ShinyHunters claimed to have stolen approximately 284 million patient data records from McKesson, a major U.S. healthcare company and pharmaceutical distributor, through voice phishing and social engineering attacks on multiple employees' Okta single sign-on accounts.
⚙️Technical Details
Affected Systems
OktaSalesforceSnowflake
Attack Vectors
voice phishingsocial engineering
💥Impact Assessment
Severity: high
Who Is at Risk
patients and healthcare providers using McKesson's services
🛡️Recommended Actions
1Implement multi-factor authentication for all employees' Okta accounts.
2Conduct regular security awareness training to prevent social engineering attacks.
3Monitor Salesforce and Snowflake environments for suspicious activity.
📦Affected Products
OktaSalesforceSnowflake
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
