All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
Security researchers have confirmed a cybersecurity incident involving McKesson, where threat actors have reportedly stolen 284 million records, including highly sensitive data such as medical information, phone numbers, and email addresses.[1]
This puts both present and past McKesson clients at risk, as cybercriminals could use this information to launch highly personalized and elaborate phishing scams, financial fraud, or even complete identity takeovers.
Here’s everything you need to know about the breach and, most importantly, the steps you can take to protect yourself.
The risks of having your health data stolen
What can you do to protect yourself
Bottom line
What data was exposed in the breach
A notorious threat group called ShinyHunters claims to have obtained 284 million records belonging to McKesson, one of the largest healthcare companies in the U.S.
As per ShinyHunters’ claim made to CyberInsider, they accessed McKesson’s systems by using vishing, or voice phishing, to target two of its employees, and then extracting data from Salesforce and Snowflake instances.
Further details on the modus operandi of the breach have not been provided by the group. ShinyHunters says it has stolen the following data:
- Patient IDs, Medicaid numbers, and medical record numbers (MRNs) belonging to patients.
- Patients’ personally identifiable information, such as phone numbers, email addresses, home addresses, Social Security numbers, full names, and dates of birth.
- Information relating to medical conditions, such as illnesses and diagnoses, disabilities, allergies, patient notes, and physician information.
- Predictive health data, such as disease-risk assessments and cancer predictions.
- Sensitive records, such as sexual orientation, terminal illness information, autopsy and cause-of-death information, and other personal status information.
- Prescription and billing records, such as shipment addresses, dates, medication orders, and tracking numbers.
- Employee records, including their phone numbers, names, addresses, email addresses, job roles, and department information.
- Doctor-patient communications.
- Information about clinics and physicians using McKesson, including names, contact details, and addresses.
The source says the 284 million records are linked to tens of millions of patients, but the exact number of people affected is not yet known.
Following the breach, ShinyHunters have demanded a ransom of $55,236,150 to prevent the files from being released. However, ShinyHunters says McKesson has not responded to the request yet.
A spokesperson said to CyberInsider, “McKesson is in the early stages of investigating a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data. Upon discovery, we immediately activated our incident response protocol, launched an investigation, and engaged leading cybersecurity experts.”
It’s worth noting that Qantas’s recent data breach was also the result of a social engineering vishing (voice phishing) scam — and there too the cybercriminals targeted unsuspecting employees for a way in.
The risks of having your health data stolen
The breached data includes both personal information and private medical records, giving threat actors plenty of ways to target victims.
Most concerningly, cybercriminals could use the stolen data to target individuals with highly personalized phishing emails or messages. These communications might contain information such as your name, Medicaid number, or other medical record references, which might make them look compelling and genuine.
For example, you could receive an email that appears to come from your insurer and claims that you need to click a link to view an updated medical report or verify information related to a recent prescription.
The link could be malicious, either installing malware on your system or taking you to a fake website controlled by the attacker, where any credentials you enter could be stolen.
Other ways hackers could exploit your data:
- Medical Identify theft: Threat actors can impersonate you and file bogus insurance claims in your name. This could not only drain your insurance benefits but also clutter your medical file with fake diagnoses and treatments, which could complicate your care and coverage for years to come.
- Financial fraud: The stolen data, such as names, email addresses, SSNs, and phone numbers, could be used to open new lines of credit in your name or take out payday loans. Victims often don’t find out about this until they’re denied credit or hit with collection calls.
- Employee-targeted secondary attacks: Since the data also includes employee records such as roles, departments, and contact information, malicious parties may use the information to orchestrate secondary attacks on employees to attempt deeper intrusions at McKesson or its partners.
What can you do to protect yourself
A data breach involving a healthcare company can be especially concerning because it can expose both your personal information and sensitive medical records.
While you have virtually no way to stop a third-party company from leaking your data — that’s up to the company’s vigilance and protection — you can follow a few cyber hygiene habits to tie up loose ends.
- Use a third-party antivirus program: A good antivirus can not only flag and remove malware you download from a phishing link, but it can also prevent you from clicking on suspicious links and visiting dangerous websites in the first place. Antiviruses with web protection can display a warning saying that the link you’re about to click might be suspicious, keeping you safe from potential phishing attacks.
- Place a credit freeze: Consider placing a credit freeze with all three major bureaus: Equifax, Experian, and TransUnion, since scammers may use your SSN and date of birth to open new lines of credit in your name. It’s free, reversible, and blocks lenders from accessing your credit reports until you lift the freeze yourself.
- Use multi-factor authentication (MFA): Multi-factor or two-factor authentication (2FA) adds an extra layer of protection to your online accounts. This will make it harder for attackers to misuse your stolen credentials, since they’d need a secondary authentication factor even after having your password.
- Check your medical records: Review your insurance statements and medical records regularly. Keep an eye on your Explanation of Benefits (EOB) statements and medical records for prescriptions, treatments, or procedures, and immediately flag anything you don’t recognize. Catching any inconsistencies early could prevent your medical file from becoming corrupted with fraudulent entries.
- Change your passwords: Immediately change your passwords for sensitive accounts such as banking, crypto wallets, or social media accounts. Consider using a password manager that not only suggests strong, unique passwords for all your accounts but also stores all of your credentials securely and even autofills them for you, saving you the trouble of remembering them.
- Use an identity theft protection service: These tools scan online databases as well as the dark web to look for your personally identifiable information and alert you if they find anything. They also typically offer identity theft restoration services, which may help you restore your identity following a data breach incident such as this.
Bottom line
McKesson’s incident response team is still active and assessing the damage from the data breach. Meanwhile, the company has yet to comment on the ransom demanded by ShinyHunters.
It’s also unclear if it would be providing any assistance to affected clients following the data breach. This means the best way to protect yourself is to take proactive steps to prevent your stolen data from being misused.
The top solutions include not clicking on any suspicious links in emails that seem to come from legitimate senders, such as insurers, using an antivirus program to block phishing attempts in their tracks, changing your account passwords, and getting an identity theft protection service.