McKesson Confirms Data Theft in Cyberattack Targeting Third-Party Cloud Applications
McKesson, a major U.S. healthcare distributor and supply chain backbone, has acknowledged a cyberattack involving unauthorized access to third-party cloud applications, resulting in data theft. The incident, claimed by the hacking group ShinyHunters, affected customers in McKesson’s oncology, multispecialty, and medical-surgical businesses. While the company has not confirmed the attackers’ statement nor independently verified the full scope of the breach it reported no disruption to its core distribution operations.
The attack aligns with a growing trend in healthcare cyber threats, where adversaries use social engineering, including voice phishing, to compromise employee accounts. Once inside, attackers exploit legitimate credentials to move undetected through systems, accessing sensitive data tied to the compromised user’s permissions. Scott Gee, deputy national adviser for cybersecurity at the American Hospital Association, noted that such activity often appears "normal," making detection difficult.
McKesson stated it has no evidence of ongoing unauthorized activity but has not determined whether the breach is material. The incident underscores the risks posed by healthcare intermediaries like McKesson and Change Healthcare, which serve as critical single points of failure due to their deep integration in billing, insurance preapprovals, and supply chains. Unlike the 2024 Change Healthcare ransomware attack which caused weeks of operational paralysis McKesson’s breach highlights the stealthy nature of account takeovers and their potential to extract data without immediate disruption.
The full impact on affected individuals remains unclear, but the attack reflects broader vulnerabilities in healthcare’s reliance on interconnected third-party platforms.
McKesson cybersecurity rating report: https://www.rankiteo.com/company/mckesson
"id": "MCK1788385186",
"linkid": "mckesson",
"type": "Cyber Attack",
"date": "1/2025",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Customers in oncology, '
'multispecialty, and '
'medical-surgical businesses',
'industry': 'Healthcare',
'location': 'U.S.',
'name': 'McKesson',
'type': 'Healthcare Distributor'}],
'attack_vector': 'Social Engineering (Voice Phishing), Compromised '
'Credentials',
'data_breach': {'data_exfiltration': 'Yes',
'sensitivity_of_data': 'High (healthcare-related)',
'type_of_data_compromised': 'Sensitive data tied to '
'compromised user permissions'},
'description': 'McKesson, a major U.S. healthcare distributor and supply '
'chain backbone, has acknowledged a cyberattack involving '
'unauthorized access to third-party cloud applications, '
'resulting in data theft. The incident, claimed by the hacking '
'group ShinyHunters, affected customers in McKesson’s '
'oncology, multispecialty, and medical-surgical businesses. '
'The attack aligns with a growing trend in healthcare cyber '
'threats, where adversaries use social engineering, including '
'voice phishing, to compromise employee accounts. Once inside, '
'attackers exploit legitimate credentials to move undetected '
'through systems, accessing sensitive data tied to the '
'compromised user’s permissions.',
'impact': {'data_compromised': 'Yes',
'downtime': 'None (no disruption to core distribution operations)',
'operational_impact': 'No disruption to core distribution '
'operations',
'systems_affected': 'Third-party cloud applications'},
'initial_access_broker': {'entry_point': 'Compromised employee accounts via '
'social engineering'},
'investigation_status': 'Ongoing (no evidence of ongoing unauthorized '
'activity, but full scope not independently verified)',
'lessons_learned': 'The incident underscores the risks posed by healthcare '
'intermediaries and the stealthy nature of account '
'takeovers, which can extract data without immediate '
'disruption. It highlights vulnerabilities in healthcare’s '
'reliance on interconnected third-party platforms and the '
'difficulty in detecting anomalous activity when attackers '
'use legitimate credentials.',
'post_incident_analysis': {'root_causes': 'Social engineering (voice '
'phishing), exploitation of '
'legitimate credentials, '
'insufficient detection of '
'anomalous activity in third-party '
'cloud applications'},
'references': [{'source': 'Cyber Incident Description'}],
'threat_actor': 'ShinyHunters',
'title': 'McKesson Confirms Data Theft in Cyberattack Targeting Third-Party '
'Cloud Applications',
'type': 'Data Breach',
'vulnerability_exploited': 'Third-party cloud applications, insufficient '
'detection of anomalous activity'}