Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

McKesson and Boston Scientific Report Disruptive Cyberattacks

McKesson and Boston Scientific are dealing with the effects of disruptive cyberattacks, although the incidents have developed differently.

McKesson confirmed that ShinyHunters targeted the company, several days after the extortion group claimed responsibility. ShinyHunters told The Register that it had accessed McKesson’s Snowflake and Salesforce instances and stolen “millions of patients’ data”. McKesson said the affected information belonged to its Oncology & Multispecialty and Medical-Surgical business units. A spokesperson said multiple employees were targeted in a vishing attack.

The group claimed to have stolen more than 284 million patient-data records and demanded $55.2 million. It said the data included patient names, postal and email addresses, phone numbers, Social Security numbers (SSN), and health-condition details. The claims remain unverified while the investigation continues.

Boston Scientific said it had removed the attackers from its infrastructure, but its investigation is ongoing. The company said new Cardiac Rhythm Management (CRM) devices implanted after August 25 cannot be activated. Data from those devices will not automatically reach remote patient-management systems.

Newly implanted ICMs must be activated with the Boston Scientific Clinic Assistant app. Boston Scientific said the devices will continue recording episodes, which can be transmitted through an in-person interrogation using the app’s “Interrogate” button. Boston Scientific has not named ShinyHunters as the attacker, and the group has not publicly claimed responsibility.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.