Texas-Based McKesson Confirms Cloud Breach, Allegedly Exposing 248,000,000 Patient Records

A pharmaceutical distributor is confirming unauthorized access to its cloud systems that resulted in data exfiltration.
McKesson says it discovered the incident on August 25th, involving unauthorized access to third-party applications.
The company says the affected data relates to a subset of customers in its oncology and multispecialty division as well as its medical-surgical unit.
The extortion group ShinyHunters claims it obtained access through vishing calls that tricked employees into revealing Okta single sign-on credentials, then pivoted to Salesforce and Snowflake platforms.
The group alleges roughly 284 million patient-record lines and about one terabyte of data were taken between August 21st and 25th, and has set a September 1st deadline for a $55 million payment to avoid publication.
McKesson says it has reasonable assurance of no ongoing unauthorized activity and continues to operate all lines of business.
McKesson has not confirmed the record count, full data types, or ransom details.
โฆ Continue reading the full article at the original source below.


