{
  "id": 6594149,
  "title": "ShinyHunters expose 6.4M in attack on medical supplier McKesson",
  "url": "https://urgent.news/2026/09/10/shinyhunters-expose-6-4m-in-attack-on-medical-supplier-mckesson-6594149",
  "topic": "science",
  "section": "Science",
  "published": "2026-09-10T13:13:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/10/shinyhunters-expose-64m-in-attack-on-medical-supplier-mckesson/5295550"
  },
  "original_language": "en",
  "account": "A recent cyberattack on medical supplier McKesson compromised the personal information of approximately 6.4 million individuals, revealed by data breach disclosure service Have I Been Pwned (HIBP). The attack came from the notorious extortion group ShinyHunters, who initially claimed to have obtained 284 million documents from McKesson in August, though HIBP could not verify this figure. Subsequently, ShinyHunters demanded $55.2 million to keep McKesson's data private, which was not paid as the data was ultimately released. HIBP reported that the exposed data encompassed a diverse range of personal details, including names, email and physical addresses, gender, dates of birth, phone numbers, employer information, and sensitive health information. This is in line with ShinyHunters' assertion that the stolen data included appointment dates, notes, and specific medical data like cancer locations. While ShinyHunters claimed to have stolen Social Security numbers, HIBP did not include them in their analysis of the leaked data. McKesson, a company that supports 3,300 oncology providers in 29 states, has not yet confirmed the exact extent of the breach or provided additional details since their last update on August 29. Meanwhile, medical device manufacturer Boston Scientific experienced a different type of cyberattack around the same time, which led to them missing their sales and earnings guidance for Q3. The company stated that their manufacturing, order fulfillment, and shipping operations had been fully restored, although work to restore some business applications is ongoing. Another healthtech company, Veradigm, also disclosed a cyberattack to US regulators after ransomware group The Gentlemen claimed responsibility. The Gentlemen stated they had stolen around 3.5 million records containing personally identifiable information, including Social Security numbers, from Veradigm.",
  "summary": "Have I Been Pwned logs leaked records spanning patients, staff, and providers",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "ShinyHunters expose 6.4M in attack on medical supplier McKesson",
        "url": "https://urgent.news/2026/09/10/shinyhunters-expose-6-4m-in-attack-on-medical-supplier-mckesson",
        "published": "2026-09-10T13:13:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}