SECURITY Signal 33
ShinyHunters claims it stole millions of patient records from McKesson's cloud environments
ShinyHunters claims to have stolen millions of patient records from McKesson's cloud-hosted Snowflake and Salesforce environments and demanded a $55 million ransom, while McKesson confirmed the breach and expects service degradation.
This breach shows how phishing and social engineering can compromise cloud-hosted healthcare data at scale. Engineers should note that even large enterprises with cloud environments like Snowflake and Salesforce are vulnerable to credential-based attacks, and that data exfiltration can lead to extortion. The incident also highlights the growing trend of healthcare companies being targeted for sensitive patient data.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
ShinyHunters claims to have stolen millions of rows of patient data from McKesson's cloud-hosted Snowflake and Salesforce environments.
The hackers used phishing and social engineering to trick employees into granting access to McKesson's network.
McKesson confirmed the breach and expects intermittent service degradation, while the hackers demanded a $55 million ransom.
THE CLUSTER
↗