McKesson Cyberattack Hits Oncology Data as Pharma Giant Warns of Service Problems

McKesson, the Texas pharmaceutical giant that delivers about one-third of all prescriptions in North America, is investigating a cyberattack that already put customer data in crooks’ hands. The company posted a public notice and filed with the Securities and Exchange Commission on Friday evening. It said it is in the early stages of looking into a cybersecurity incident involving an unnamed third-party application. Hackers got into that application and started pulling data out.

If you fill a prescription, sit in a cancer clinic, or run a small medical practice, this is not some distant IT story. This is the plumbing of American healthcare taking a hit.

What McKesson Is Telling Customers

Chief technology officer Francisco Fraga used the usual corporate fog. “At this time, customers may experience intermittent service degradation that we believe may be related to this incident,” he said. “We are aware of these issues and continue to monitor the situation closely.”

That means some systems are acting up, and they think the breach is why.

On Saturday, McKesson said the attackers took data associated with customers in the oncology and surgical business units. Fraga said the company will provide credit monitoring and identity protection to customers whose data was stolen. McKesson also said it has “reasonable assurance” the hackers are no longer inside its systems.

“Customers can continue to connect to and use our systems and services as intended,” Fraga said. The company is not proactively disconnecting systems, the step outfits usually take when ransomware is spreading and they need to contain the mess. He told customers to contact McKesson if they hit technical problems. The company said it is still investigating and did not answer questions about the incident when reached for comment.

ShinyHunters Claims the Job

The ShinyHunters cybercriminal group took credit for the attack on Friday night and threatened leaks on their blog. This crew has spent more than two years attacking and extorting some of the largest companies in the world.

Earlier this year, the FBI warned that hackers linked to ShinyHunters were demanding substantial ransom payments from companies after stealing data through compromises involving Salesforce environments.

The same group caused chaos across the U.S. in May with an attack on a widely used educational software suite. In April, they stole the information of more than four million people after attacking the world’s largest medical device company.

Other victims named in that reporting include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill, ADT, and gaming company Rockstar.

A Company That Moves a Third of North America’s Prescriptions

McKesson reported $106 billion in revenue last quarter. About one-third of all prescriptions in North America are delivered by the company. It distributes pharmaceuticals, produces drugs for oncology patients, and manufactures medical-surgical supplies and laboratory equipment.

This is also not a one-off in healthcare. McKesson is the latest large healthcare company attacked this year after medical device giants Boston Scientific and Medtronic both reported cybersecurity incidents. Another large medical device firm, Stryker, was hit earlier this year too.

The pattern is ugly and simple. Healthcare has to stay online because people need medicine and surgery. Attackers know that. Vendors and third-party apps sit on the same network as the stuff that actually matters. When that link fails, patients and small clinics eat the risk while the giant talks about “service degradation.”

What You Should Do If This Touches You

You do not need a security team to take a few practical steps. The hole was a third-party application. The stolen records sit in oncology and surgical customer data. Credit monitoring is the standard offer, and it is not the same as locking things down yourself.

  • If you are a pharmacy, hospital, or clinic that uses McKesson, watch for odd outages and call them if a service misbehaves.
  • If your information may have been in the oncology or surgical units, enroll in the identity protection they offer, then freeze your credit with the bureaus anyway.
  • Read your explanation of benefits and pharmacy records for charges or refills you did not authorize.
  • Treat “reasonable assurance” the attackers are gone as an update, not a finish line. Investigations move. So do leak sites.
  • Ask your providers which vendors hold your data. The weak door is often a tool nobody on the floor has ever heard of.

Big healthcare companies will keep filing SEC notices and offering monitoring. Regular people still have to watch their own accounts. That is the system we have right now, and it is not working for the folks who actually get the chemo and the stitches.

Primary Source: https://therecord.media/mckesson-cyberattack-ransomware-pharma

Leave a Reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.