McKesson has confirmed a breach by extortion group ShinyHunters, though the attacker's claim of 284 million stolen patient records has not been verified by the company.
ShinyHunters told The Register it broke into McKesson's Snowflake and Salesforce instances after targeting several employees with vishing calls. McKesson confirmed the intrusion and said the exposed data came from its Oncology and Multispecialty and Medical-Surgical business units, including patient names, addresses, phone numbers, Social Security numbers, and health details. The group is demanding $55.2 million and says it holds more than 284 million records, but McKesson has not confirmed the scale of the theft. Separately, Boston Scientific disclosed its own breach last week, saying it has removed the attackers from its network though the investigation continues; the company has not attributed the intrusion to ShinyHunters, and the group has not claimed it.
The Boston Scientific incident is the more unsettling one. New cardiac rhythm devices implanted after August 25 cannot be activated remotely, meaning patients need an in-person visit with the Clinic Assistant app to get their monitors talking to remote care systems. Two healthcare giants breached in the same week is a reminder that hospital-adjacent vendors, not just hospitals, are now prime targets for extortion crews, and that a breach can reach past data and into device functionality patients actually rely on.
ShinyHunters has a habit of inflating stolen-record counts to pressure victims into paying, so treat the 284 million figure as a negotiating tactic until McKesson says otherwise.