{
  "id": 6589660,
  "title": "ShinyHunters expose 6.4M in attack on medical supplier McKesson",
  "url": "https://urgent.news/2026/09/10/shinyhunters-expose-6-4m-in-attack-on-medical-supplier-mckesson",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-10T13:13:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/09/10/shinyhunters-expose-64m-in-attack-on-medical-supplier-mckesson/5295550"
  },
  "original_language": "en",
  "account": "McKesson, a leading medical supplier with a presence in 29 states, fell victim to a cyberattack in August, impacting an estimated 6.4 million individuals. The extent of the breach was first disclosed by Have I Been Pwned (HIBP), which obtained data stolen by the extortion group ShinyHunters. Initially, ShinyHunters claimed to have acquired 284 million documents, though HIBP did not verify this figure. The group demanded $55.2 million for the data's return, a sum that remained unpaid, leading to the leakage of personal information.\n\nThe compromised data encompassed a wide range of individuals and roles, including patients, staff, and healthcare providers. It included names, email addresses, physical addresses, genders, dates of birth, phone numbers, employer details, and sensitive health information. While ShinyHunters alleged the theft of Social Security numbers (SSNs), HIBP did not include these in its analysis.\n\nMcKesson, which supports 3,300 oncology providers, has not publicly confirmed the full scale of the breach or provided further details since its initial update on August 29. Meanwhile, Boston Scientific, another medical device maker, also suffered a cyberattack around the same time as McKesson. However, the disruption caused by the Boston Scientific attack led the company to miss its sales and earnings guidance for Q3. The disruption was limited to manufacturing, order fulfillment, and shipping operations, which were fully restored. Work to restore some business applications is ongoing. Healthtech company Veradigm also disclosed a cyberattack to US regulators, revealing attackers gained credentials from a third-party vendor and accessed a company API to steal patient data, impacting around 3.5 million records containing PII, including SSNs.",
  "summary": "Have I Been Pwned logs leaked records spanning patients, staff, and providers",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "ShinyHunters expose 6.4M in attack on medical supplier McKesson",
        "url": "https://urgent.news/2026/09/10/shinyhunters-expose-6-4m-in-attack-on-medical-supplier-mckesson-6594149",
        "published": "2026-09-10T13:13:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}