ShinyHunters expose 6.4M in attack on medical supplier McKesson

Summary

The threat actor group ShinyHunters has claimed responsibility for an attack on the medical supplier McKesson, exposing approximately 6.4 million records. The leaked data includes information on patients, staff, and healthcare providers, and has been logged by Have I Been Pwned.

IFF Assessment

FOE

This breach exposes sensitive personal and healthcare information, posing a significant risk to individuals and the healthcare system.

Defender Context

This incident highlights the ongoing threat of data breaches targeting critical infrastructure like healthcare suppliers. Defenders should remain vigilant against credential stuffing, phishing, and other attack vectors that could lead to such large-scale data exfiltration. Organizations must prioritize robust access controls and continuous monitoring to detect and respond to unauthorized access.

Read Full Story →