McKesson Confirms Cyber Incident After ShinyHunters Claims Patient‑Data Theft
What Happened – McKesson disclosed a cyber incident after the ShinyHunters hacking group publicly claimed to have exfiltrated patient‑health records from the company’s systems. The breach is confirmed by McKesson’s own statement and is being investigated by law‑enforcement.
Why It Matters for Trust & Control Assurance
- The incident tests the effectiveness of continuous vendor‑risk monitoring and evidence‑collection practices that a control‑assurance program expects from third‑party service providers.
- Demonstrable incident‑response controls (e.g., documented detection, containment, and forensic evidence) become critical evidence during audits and regulator reviews.
- Ongoing assurance of vendor security posture helps organizations meet multiple framework requirements with a single control objective (e.g., “Incident response and handling”).
Who Is Affected – Healthcare providers, health‑tech platforms, and any organization that relies on McKesson’s supply‑chain or data services.
Recommended Actions
- Map the incident‑response control objective to your audit‑readiness framework and verify that you have recent evidence of detection, containment, and post‑incident analysis for all critical vendors.
- Initiate a third‑party risk review of McKesson, requesting up‑to‑date security attestations and evidence of remediation.
- Update your incident‑response playbooks to include supply‑chain breach scenarios and ensure logging is retained for forensic review.
Technical Notes – The public claim references stolen patient‑health records; no specific vulnerability or CVE has been disclosed. The attack vector remains unconfirmed, though ShinyHunters typically leverages credential‑theft or mis‑configured cloud storage. Source: Malwarebytes Labs – A week in security (Aug 31 – Sep 6)