Hackers say McKesson data breach exposed records from tens of millions of patients

September 2, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: healthexec.com

Threat Risk: High
Victim: Healthcare and pharmaceutical supply chain
Incident: Data breach resulting from credential theft via voice-phishing.
Impact: Potential exposure of 284 million records containing sensitive PII and detailed medical histories.
Attacker: ShinyHunters
Analysis: Threat actors leveraged vishing to harvest employee credentials, granting them unauthorized access to Salesforce and Snowflake environments. The stolen dataset allegedly contains a vast array of PII and sensitive clinical data, including oncology and surgical records. This incident highlights the persistent risk of social engineering targeting privileged cloud access.
Recommendations: Implement phishing-resistant MFA, such as FIDO2 security keys, across all cloud service portals.; Conduct targeted vishing awareness training for employees with administrative access to sensitive data.; Audit third-party cloud storage permissions and enforce the principle of least privilege.
Source: HealthExec

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *