
A hacking group demanded $55 million from one of America’s largest pharmaceutical distributors after walking out with what it claims are millions of patient records. That’s not a hypothetical threat. It already happened. And according to TechCrunch, the group responsible is ShinyHunters, one of the most active data-extortion crews operating right now.
McKesson, the Texas-based company that distributes pharmaceuticals, medical supplies, and health technology to hospitals across the United States, confirmed the breach on its website. Hackers broke into several of its cloud-hosted accounts and exfiltrated data. The company’s chief technology officer, Francisco Fraga, told customers in a separate notice that the stolen data touches its oncology, multispecialty, and medical-surgical units. In other words, some of the most sensitive patient populations imaginable.
ShinyHunters told TechCrunch they got in through phishing and social engineering, tricking employees into granting network access. This is a known playbook for the group. Once inside, they say they pulled data from McKesson’s cloud-hosted Snowflake and Salesforce environments. The haul reportedly includes names, addresses, Social Security numbers, diagnoses, medications, allergies, and clinical notes. Employee home addresses were also taken. TechCrunch reviewed samples of the stolen data and verified a small portion against public records.
McKesson’s spokesperson said the company “continues to operate in all lines of business” and believes there is no ongoing unauthorized access. But the company declined to answer basic questions, including how many people were affected. That silence is itself an answer of sorts. When a company handling cancer patient records won’t say how many individuals are at risk, that’s a failure of transparency that compounds the original security failure.
This breach does not exist in isolation. Healthcare has been under sustained attack. Boston Scientific had its network knocked offline last week. Stryker dealt with hackers remotely wiping thousands of employee devices. Abbott Laboratories and Medtronic have both faced attacks. CareCloud and TriZetto each had breaches hitting over three million patients. ShinyHunters also claimed responsibility for breaches at Amazon-owned One Medical and dental insurer DentaQuest.
The pattern is clear. Hackers have figured out that medical data is extraordinarily valuable for extortion because companies fear regulatory penalties, reputational damage, and the harm that exposure could cause patients. So the attacks keep coming, and the victims keep being people who had no choice but to hand their most private health details to these companies.
McKesson’s cloud environment held data on cancer patients. Someone phished their way into it. That’s the reality. And until healthcare companies face real consequences for weak access controls and slow breach disclosure, this will keep happening.