LIVE · cybersecurity feed
Live wire
breach

McKesson Confirms Data Breach as Attacker Deadline Looms

The ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems. The post McKesson Confirms Data Breach as Attacker Deadline Looms appeared first on SecurityWeek.

zeroday.news ·

McKesson has confirmed a data breach following claims by the ShinyHunters extortion group. The group asserts they have stolen 284 million records from the company's systems and has set a deadline for their demands. The confirmation from McKesson indicates an active incident response effort is underway regarding the reported data compromise.

The ShinyHunters group, known for its data theft and extortion tactics, publicly claimed responsibility for the breach. While the specific nature of the 284 million records was not detailed, such large-scale breaches often involve a mix of personal identifiable information (PII), potentially including names, addresses, email addresses, and other sensitive data depending on the affected systems. The group's typical modus operandi involves exfiltrating data and then threatening to leak it publicly if a ransom is not paid by a specified deadline.

McKesson, a major player in the healthcare supply chain and information technology, operates extensive systems that manage sensitive patient and operational data. A breach of this magnitude could potentially impact various facets of their operations, from pharmaceutical distribution to healthcare IT solutions. The confirmation of the breach by McKesson suggests that internal investigations have corroborated at least some aspect of the ShinyHunters' claims, prompting a public acknowledgment.

The technical mechanism behind such large-scale data exfiltration often involves exploiting vulnerabilities in network perimeter defenses, compromising internal systems through phishing or other social engineering tactics, or leveraging misconfigured cloud storage or databases. Once initial access is gained, attackers typically move laterally within the network to identify and exfiltrate valuable data stores. The sheer volume of records claimed suggests access to significant data repositories.

For organizations facing similar threats, typical mitigation guidance includes robust network segmentation, multi-factor authentication for all critical systems, regular security audits, and comprehensive employee training on cybersecurity best practices. Incident response plans are crucial for containing breaches, eradicating threats, and recovering compromised systems. Furthermore, organizations are often advised to engage with law enforcement and cybersecurity experts to manage the fallout from extortion attempts.

The incident underscores the persistent threat posed by financially motivated cybercriminal groups like ShinyHunters, who continuously target organizations across various sectors for data theft and extortion. The healthcare sector, in particular, remains a prime target due to the sensitive and valuable nature of the data it handles. This event serves as a reminder of the critical importance of proactive cybersecurity measures and resilient incident response capabilities in today's threat landscape.

breach
ShareXLinkedInWhatsAppFacebook

More News

view all →
ransomware

Berlin confirms data theft after Rhysida ransomware attack claims

Berlin's city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. [...]

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

malware

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names WEEVILPROXY or MeadowLocust). Its campaign activity dates back to March 2024 [1]; Check Point Research has been tracking the malware since early […] The post Breaking

security

FulcrumSec claims Manchester Airports hack, theft of 86 GB of data

FulcrumSec claims it stole 86 GB of data from Manchester Airports Group. BleepingComputer validated one traveller's record, while samples revealed detailed customer, booking, and travel information beyond what MAG initially disclosed. [...]

malware

Anthropic warns infostealer malware is hijacking Claude sessions to drain usage

Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage. [...]