McKesson Confirms Data Theft in Cyberattack on Third-Party Applications
Summary
Drug distributor and supply giant McKesson said an unauthorised party gained access to its third-party applications and stole data, affecting customers in its oncology, multispecialty and medical-surgical businesses, with employee data also taken; the company has 'reasonable assurance' there is no ongoing activity and has not yet determined materiality. ShinyHunters claimed responsibility, telling BleepingComputer it used voice phishing to compromise employee accounts and reach cloud applications, demanding a reported $55 million. The number affected remains unknown, but McKesson's position โ roughly 40,000 daily deliveries to nearly every US care site โ makes it an unusually connected healthcare intermediary, and Health-ISAC flagged the vishing-to-SSO pattern as a ShinyHunters signature in July; the vendor-chain risk mirrors Australian concerns flagged in this digest's context.