McKesson confirms cybersecurity incident as hackers claim millions of patient records stolen

Healthcare giant McKesson Corporation confirmed on Friday that it was investigating a cybersecurity incident tied to third-party applications that led to unauthorized access and theft of data.

"Upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to assist in our response," the company said in a disclosure on its website posted Friday. "Our investigation remains ongoing, and we are working to fully ascertain the nature and scope of the incident so that we can provide accurate and concrete information as it becomes available."

On Saturday, the company posted an update confirming that hackers accessed and exfiltrated certain data "associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units."

The company said it was continuing to serve customers across all its lines of business and was accepting orders. McKesson distribution centers remain operational, and the company continues to ship products across its distribution network, it said.

The company said it has "reasonable assurance" of no ongoing unauthorized activity in its systems. 

In a filing with the U.S. Securities and Exchange Commission, the company said it discovered a cybersecurity incident affecting its information systems on August 25. 

McKesson is a major distributor of pharmaceuticals, medical supplies and healthcare technology services. In its disclosure, the company did not specify the type of data that was exfiltrated, who was behind the attack and the number of people affected.

CyberInsider reported Friday that ShinyHunters, a cyber extortion group, claims it compromised McKesson and obtained data on over 284 million patient records, "including highly sensitive medical, identity, prescription, and healthcare provider information."

CyberInsider said it reviewed samples privately provided by the threat actor that appear consistent with the types of information described in the data breach claims.

According to ShinyHunters, the allegedly stolen patient data includes identity and contact information, such as full names, home addresses and Social Security numbers, healthcare identifiers, such as patient IDs, medical information, predictive health data and prescription and billing records, CyberInsider reported.

The hacking group is demanding approximately $55 million from the company not to release the stolen files, which it is threatening to do unless the company contacts them to start payment negotiations by September 1, SecurityWeek reported.

The data theft and extortion group has targeted and stolen data from other healthcare companies including Baxter International, Amazon One Medical and Medtronic, The HIPAA Journal reported.

McKesson said its investigation remains ongoing as it continues to fully ascertain the scope of information that may have been accessed or acquired.

The company said it will provide complimentary credit monitoring and identity protection services, as well as a dedicated information line to answer questions and provide support to partners, customers and their patients whose data was exfiltrated.