Healthcare cyberattacks hit pacemakers and millions of patient records
McKesson admits breach as ShinyHunters demands $55.2M
Healthcare firms Boston Scientific and McKesson are grappling with separate cyberattacks that have exposed sensitive patient records and disrupted medical device operations globally. Boston Scientific, a medical-device manufacturer, disclosed on Friday that its IT systems had been compromised by unknown attackers last week, rendering new pacemakers and heart devices unable to transmit remote monitoring data.
These devices, implanted after the August 25 breach, are unable to establish communication with remote patient management systems, preventing the transmission of available device data. Patients can still transmit recorded episodes to remote systems via the Clinic Assistant app. The company has hired CrowdStrike to aid in the investigation and restoration efforts, but provided no timeline for full recovery.
McKesson, a pharmaceutical and medical supply company, confirmed on Saturday that its Snowflake and Salesforce instances had been breached by ShinyHunters, an extortion group. The group is demanding $55.2 million to prevent the release of stolen data, which reportedly includes over 284 million patient records containing sensitive information such as full names, home addresses, phone numbers, dates of birth, Social Security numbers, and medical details.
McKesson's distribution centers remain operational, and the company claims to have "reasonable assurance" that the attackers no longer have access to its systems.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.
This story
This is one outlet's version. Read the fullest account.