Healthcare Cyberattacks Expose 284M Patient Records
McKesson and Boston Scientific grapple with breaches exposing patient data and disrupting implanted cardiac devices.
Last week, two major healthcare organizations suffered highly disruptive cyberattacks: Boston Scientific, and McKesson. We now have more details about both those attacks, and it seems at least one is the work of the infamous ShinyHunters extortion group.
ShinyHunters Claims McKesson Breach
McKesson confirmed having been struck by ShinyHunters, just a few days after the threat actor claimed responsibility. The group told The Register they broke into the company’s Snowflake and Salesforce instances and stole “millions of patients’ data”.
The company later issued a statement, saying the stolen data belonged to its Oncology & Multispecialty and Medical-Surgical business units. A spokesperson told The Register multiple employees were targeted with a vishing attack.
Scope of the Data Theft
The group told the publication it stole more than 284 million records of patient data and demanded $55.2 million from the victims. They are saying the stolen batch includes patient tames, postal and email addresses, phone numbers, Social Security numbers (SSN), and details regarding their health condition. Whether the claims are true, and to what extent, remains to be seen after the investigation.
Here are the key numbers reported:
- 284 million patient records allegedly stolen
- $55.2 million ransom demand
- Two business units affected: Oncology & Multispecialty and Medical-Surgical
Boston Scientific's Response
Boston Scientific, on the other hand, said it successfully removed the attackers from its infrastructure, but added that the investigation into the attack remains ongoing. It also said that new Cardiac Rhythm Management (CRM) devices, implanted after August 25, cannot be activated, and the data they generate will not automatically be transmitted to remote patient management systems.
“Newly implanted ICMs (insertable cardiac monitors) must be activated using the Boston Scientific Clinic Assistant app to enable the ICM to properly record episodes,” it explained. “New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app. Episodes will continue to be recorded by the ICM and can be transmitted to the remote monitoring system via an in-person interrogation with the Clinic Assistant app by selecting the “Interrogate” button.”
Boston Scientific is yet to name ShinyHunters as the perpetrators, and the group has not yet publicly claimed responsibility for the attack.
Implications for Healthcare Security
These attacks highlight the growing threat to healthcare organizations, which hold vast amounts of sensitive data that is highly valuable to cybercriminals. The disruption to cardiac device functionality in particular shows the potential for real-world physical harm when such systems are compromised.
For patients and providers, the impact can be severe. For those affected by the McKesson breach, the exposure of Social Security numbers and health details could lead to identity theft and fraud. For Boston Scientific, the inability to activate implanted devices means patients may require additional procedures or in-person visits, creating delays in critical care.
As the investigations continue, it's clear that the healthcare sector must prioritize robust cybersecurity measures to protect both data and patient safety. The incidents serve as a stark reminder that the consequences of a breach can extend far beyond the digital realm.
Sources
- TechRadar Original source
Continue Reading
Fake installers target Windows update, Defender
Microsoft details campaign impersonating vendors to weaken Windows Update and Defender.
Malware Suspect Extradited Over Freelancer Scam
Russian man faces US charges for malware campaign that hit 80,000 freelance platform users.
Brazilian sites hijacked in SEO fraud ruse
Chinese-speaking Gambling Goblin group turns Brazilian government sites into SEO and phishing infrastructure.