The ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems. The post McKesson Confirms Data Breach as Attacker Deadline Looms appeared first on SecurityWeek.

McKesson has confirmed a data breach following claims by the ShinyHunters extortion group. The group asserts they have stolen 284 million records from the company's systems and has set a deadline for their demands. The confirmation from McKesson indicates an active incident response effort is underway regarding the reported data compromise.
The ShinyHunters group, known for its data theft and extortion tactics, publicly claimed responsibility for the breach. While the specific nature of the 284 million records was not detailed, such large-scale breaches often involve a mix of personal identifiable information (PII), potentially including names, addresses, email addresses, and other sensitive data depending on the affected systems. The group's typical modus operandi involves exfiltrating data and then threatening to leak it publicly if a ransom is not paid by a specified deadline.
McKesson, a major player in the healthcare supply chain and information technology, operates extensive systems that manage sensitive patient and operational data. A breach of this magnitude could potentially impact various facets of their operations, from pharmaceutical distribution to healthcare IT solutions. The confirmation of the breach by McKesson suggests that internal investigations have corroborated at least some aspect of the ShinyHunters' claims, prompting a public acknowledgment.
The technical mechanism behind such large-scale data exfiltration often involves exploiting vulnerabilities in network perimeter defenses, compromising internal systems through phishing or other social engineering tactics, or leveraging misconfigured cloud storage or databases. Once initial access is gained, attackers typically move laterally within the network to identify and exfiltrate valuable data stores. The sheer volume of records claimed suggests access to significant data repositories.
For organizations facing similar threats, typical mitigation guidance includes robust network segmentation, multi-factor authentication for all critical systems, regular security audits, and comprehensive employee training on cybersecurity best practices. Incident response plans are crucial for containing breaches, eradicating threats, and recovering compromised systems. Furthermore, organizations are often advised to engage with law enforcement and cybersecurity experts to manage the fallout from extortion attempts.
The incident underscores the persistent threat posed by financially motivated cybercriminal groups like ShinyHunters, who continuously target organizations across various sectors for data theft and extortion. The healthcare sector, in particular, remains a prime target due to the sensitive and valuable nature of the data it handles. This event serves as a reminder of the critical importance of proactive cybersecurity measures and resilient incident response capabilities in today's threat landscape.

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]