LIVE · cybersecurity feed
Live wire
Perturbation Probing: A New Diagnostic for the Fragility of LLM SafetyResearcher shows how Claude Code can be tricked simply by asking it to summarize a websiteAustralian Police Arrest Alleged TeamPCP Cybercrime MastermindsNearly 700 rogue AI agents coordinated in the Hugging Face attackCISA orders feds to patch Citrix NetScaler RCE flaw by SaturdayUS Disrupts Chinese Hacking Platform Used in Military and Critical Infrastructure AttacksCritical Avada WordPress theme flaw enables zero-click RCECVE-2026-15409 · Edge infrastructure under siege: what two independent datasets reveal about who's exploiting your perimeterAnonyMousKIT phishing-as-a-service uses AI voice calls to steal iPhone passcodesCVE-2026-60004 · Hackers now exploit critical Gitea flaw in code injection attacks
breach

McKesson discloses breach after ShinyHunters claims patient data theft

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]

zeroday.news ·

McKesson, a major U.S. healthcare and pharmaceutical distribution company, has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration. The ShinyHunters extortion group has claimed responsibility for the attack, asserting that it stole approximately 284 million patient data records.

The company first detected the incident on August 25, 2026, and subsequently filed a Form 8-K with the U.S. Securities and Exchange Commission, confirming the breach. McKesson stated that its investigation is in its early stages and that it has not yet determined the incident's material impact on the company's financial condition or operations. Customers have been notified that the incident involved third-party applications and unauthorized data access, and the company is working with cybersecurity experts to understand the full scope. McKesson has also warned of potential intermittent service degradation for customers, which is believed to be related to the attack.

ShinyHunters informed a cybersecurity publication that they executed the attack through voice phishing, or vishing, social engineering tactics targeting multiple McKesson employees. While specific technical details of the social engineering campaign were not fully disclosed by the group, it was reported that the domain mckesson[.]claims was utilized. This domain pattern aligns with a broader ShinyHunters campaign previously documented by ReliaQuest's Threat Research team, which involved registering .claims domains incorporating targeted company names to impersonate help desks and IT teams.

The vishing attacks allegedly led to the compromise of several employees' Okta single sign-on accounts. ShinyHunters claims these compromised credentials were then used to access McKesson's Salesforce and Snowflake environments. The group asserts it fully compromised the Salesforce environment, including support cases, and exfiltrated a significant volume of patient-related data from Snowflake.

According to ShinyHunters, approximately 1 terabyte of data was exfiltrated over four days, between August 21 and August 25. The group clarified that the figure of 284 million refers to raw data records or lines, not necessarily unique individuals, as they have not yet fully analyzed the stolen data to determine the number of unique people affected.

ShinyHunters claims the stolen information encompasses a wide range of sensitive data, including names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment details, and physician information. The group also alleges the data includes information on deceased and terminally ill patients, prescription and medication shipment details, invoices, employee information, Salesforce records, internal communications, and data pertaining to healthcare providers and clinics utilizing McKesson's services. McKesson has not publicly confirmed the specific types of data stolen.

The extortion group stated that it contacted McKesson on August 25, after completing the data theft, demanding a ransom of $55,236,150 with a 72-hour deadline for a response. ShinyHunters claims McKesson did not respond to or negotiate the demand.

This incident follows a series of data-theft attacks attributed to ShinyHunters targeting healthcare and health technology organizations. Health-ISAC recently issued a warning to the healthcare sector about increasing ShinyHunters activity involving social engineering to compromise corporate accounts and gain access to cloud and SaaS platforms. Other healthcare technology companies reportedly targeted by ShinyHunters in recent data-theft attacks include Medtronic, DentaQuest, iRhythm, OneMedical, and AdaptHealth.

breachhealthcare
ShareXLinkedInWhatsAppFacebook

More News

view all →
ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

aicritical

Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety

New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first on Unit 42.

security

Berlin Refuses to Pay Hackers Who Stole Data From the City's State Network

Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in the portfolio of the Senate Department for Mobility, Transport, Climate Protection and Environment

aihigh

Researcher shows how Claude Code can be tricked simply by asking it to summarize a website

A security researcher has demonstrated a method to trick Anthropic's Claude Code, specifically the Opus 5 model in Auto Mode, into executing arbitrary code. The attack involves prompting the AI to summarize a malicious website, which leads it to bypass its intended tools and use `curl` to download a ZIP archive. This archive contains a Python file that exploits module shadowing to execute a remote payload, potentially leading to further agent creation or system compromise.

ai

Offensive Security Investments Surge as AI Threats Increase

Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.