Dive Brief:
- Drug distributor and supply company McKesson said an unauthorized person gained access to its third-party applications and stole data, affecting customers in its oncology, multispecialty and medical-surgical businesses.
- The company said it has reasonable assurance there is no ongoing unauthorized activity, and its businesses and distribution network remain operational. McKesson has not determined if the incident is material, according to a securities filing.
- The hacking group ShinyHunters has claimed responsibility for the breach, telling cybersecurity news outlet BleepingComputer it used voice phishing to compromise employee accounts and access cloud applications. McKesson has not confirmed the group’s statement, which BleepingComputer said it could not independently verify. The number of people affected remains unknown.
Dive Insight:
The full scope of the breach remains unclear, but McKesson occupies an unusually connected position in the healthcare system. The company describes itself as a logistical and operational backbone of the industry, and says it makes about 40,000 deliveries each day to nearly every type of care site nationwide. So far, McKesson says the incident has not disrupted its core business or distribution operations.
The attack method described by ShinyHunters would fit a pattern that healthcare cyber experts have been sounding the alarm about. The Health Information Sharing and Analysis Center, a nonprofit cyber group, said in July that ShinyHunters was increasingly using voice phishing and other methods to take over single-sign-on accounts and compromise connected cloud applications.
These attacks can be particularly difficult to detect because activity from a compromised employee account can appear legitimate, Scott Gee, deputy national adviser for cybersecurity and risk at the American Hospital Association, told Healthcare Dive via email. “An employee account moving around an environment looks ‘normal’ and often goes unnoticed,” he said.
Once an account is compromised, attackers can access everything the employee is authorized to reach, Gee added. Recent healthcare breaches have followed similar routes: AdaptHealth disclosed in July that a cybercriminal used social engineering to access cloud-based applications and steal health information.
The McKesson incident is not an apples-to-apples comparison to the operational collapse caused by the 2024 Change Healthcare ransomware attack, which devastated the healthcare industry for weeks. But the incidents illustrate different forms of risk created by deeply embedded healthcare intermediaries. Gee called Change Healthcare a “single point of failure” because of the large share of billing and insurance preapproval transactions it processed.