McKesson, a pharmaceutical and healthcare technology company, announced it is investigating a cybersecurity incident. The attack involves an unnamed third-party application, leading to 'service degradation' for customers. The company filed documents with the SEC and issued a public notice regarding the incident.
McKesson confirmed that hackers gained access to the application and exfiltrated data. An update from the company stated that the exfiltrated data is associated with customers in its oncology and surgical business units. McKesson plans to offer credit monitoring and identity protection services to affected customers.
The ShinyHunters cybercriminal group claimed credit for the attack, threatening to leak data. This group has a history of attacking and extorting large companies, with previous victims including Carnival Cruises, Ticketmaster, and AT&T. The FBI previously warned about ShinyHunters demanding ransoms after compromising Salesforce environments.
McKesson's CTO, Francisco Fraga, stated that while customers may experience intermittent service degradation, they can continue to use systems and services. The company has received 'reasonable assurance' that the attackers are no longer within their systems and is not proactively disconnecting systems, which is common in ransomware attacks. The investigation is ongoing, and McKesson has not provided further details.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Pharmaceutical and healthcare technology company McKesson is investigating a cyberattack on a third-party application that caused service degradation and data exfiltration from its oncology and surgical business units. The ShinyHunters cybercriminal group has claimed responsibility for the attack, which could impact customer data and service availability for a major healthcare provider.