Breaking
Cyber CrimeDeveloping Story

Healthcare Cyberattacks Expose 284M Patient Records

McKesson and Boston Scientific grapple with breaches exposing patient data and disrupting implanted cardiac devices.

··1 day ago·2 min read
silhouette photography of man
Photo by Chris Yang on Unsplash

Last week, two major healthcare organizations suffered highly disruptive cyberattacks: Boston Scientific, and McKesson. We now have more details about both those attacks, and it seems at least one is the work of the infamous ShinyHunters extortion group.

ShinyHunters Claims McKesson Breach

McKesson confirmed having been struck by ShinyHunters, just a few days after the threat actor claimed responsibility. The group told The Register they broke into the company’s Snowflake and Salesforce instances and stole “millions of patients’ data”.

The company later issued a statement, saying the stolen data belonged to its Oncology & Multispecialty and Medical-Surgical business units. A spokesperson told The Register multiple employees were targeted with a vishing attack.

Scope of the Data Theft

The group told the publication it stole more than 284 million records of patient data and demanded $55.2 million from the victims. They are saying the stolen batch includes patient tames, postal and email addresses, phone numbers, Social Security numbers (SSN), and details regarding their health condition. Whether the claims are true, and to what extent, remains to be seen after the investigation.

Here are the key numbers reported:

  • 284 million patient records allegedly stolen
  • $55.2 million ransom demand
  • Two business units affected: Oncology & Multispecialty and Medical-Surgical

Boston Scientific's Response

Boston Scientific, on the other hand, said it successfully removed the attackers from its infrastructure, but added that the investigation into the attack remains ongoing. It also said that new Cardiac Rhythm Management (CRM) devices, implanted after August 25, cannot be activated, and the data they generate will not automatically be transmitted to remote patient management systems.

“Newly implanted ICMs (insertable cardiac monitors) must be activated using the Boston Scientific Clinic Assistant app to enable the ICM to properly record episodes,” it explained. “New ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app. Episodes will continue to be recorded by the ICM and can be transmitted to the remote monitoring system via an in-person interrogation with the Clinic Assistant app by selecting the “Interrogate” button.”

Boston Scientific is yet to name ShinyHunters as the perpetrators, and the group has not yet publicly claimed responsibility for the attack.

Implications for Healthcare Security

These attacks highlight the growing threat to healthcare organizations, which hold vast amounts of sensitive data that is highly valuable to cybercriminals. The disruption to cardiac device functionality in particular shows the potential for real-world physical harm when such systems are compromised.

For patients and providers, the impact can be severe. For those affected by the McKesson breach, the exposure of Social Security numbers and health details could lead to identity theft and fraud. For Boston Scientific, the inability to activate implanted devices means patients may require additional procedures or in-person visits, creating delays in critical care.

As the investigations continue, it's clear that the healthcare sector must prioritize robust cybersecurity measures to protect both data and patient safety. The incidents serve as a stark reminder that the consequences of a breach can extend far beyond the digital realm.

#healthcare#data breach#shinyhunters#mckesson#boston scientific#patient records

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories