McKesson Corporation is investigating a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration, while the ShinyHunters extortion group claims it stole approximately 284 million patient-related records from the healthcare and pharmaceutical distribution company.
McKesson said it discovered the incident on August 25 and immediately activated its incident-response procedures. The company has brought in external cybersecurity specialists to assist with the investigation, which it said remains in its early stages.
In a filing with the U.S. Securities and Exchange Commission, McKesson said it has not determined that the incident is material or that it has had, or is reasonably likely to have, a material impact on its financial condition or operations.
The company confirmed in a separate customer notice that the incident involved unauthorized access to third-party applications and the exfiltration of data. McKesson has not identified the affected applications, disclosed how the attackers obtained access, or confirmed what information was taken.
Customers could also experience intermittent service degradation believed to be related to the incident. McKesson said it was not proactively disconnecting systems within its environment.
ShinyHunters claims employee accounts were compromised
ShinyHunters claims it obtained initial access through voice-phishing, or vishing, attacks targeting multiple McKesson employees.
According to the group, the attacks resulted in the compromise of several employee Okta single sign-on accounts. Those accounts were allegedly used to access McKesson's Salesforce and Snowflake environments.
The group claims it obtained extensive access to Salesforce, including support cases, and extracted a larger volume of patient-related information from Snowflake.
ShinyHunters alleges that approximately 1 TB of data was removed over four days, from August 21 through August 25.
The group has claimed that the Snowflake data contained roughly 284 million patient-related records. However, it later clarified that this figure represents individual database records or lines, rather than 284 million unique patients.
ShinyHunters also said it has not completed its analysis of the stolen material and therefore cannot determine how many individuals are represented in the dataset.
The alleged information includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers and medical record numbers. The group also claims the data contains medication and allergy information, illnesses, disabilities, appointments, physician details, prescriptions and medication shipments.
Other allegedly stolen material includes information relating to deceased and terminally ill patients, invoices, employee data, Salesforce records, internal communications, and information about healthcare providers and clinics using McKesson's services.
McKesson has not confirmed any of these specific data categories, and the claims about the stolen information have not been independently verified.
McKesson domain follows ShinyHunters pattern
The alleged campaign also involved the "mckesson[.]claims" domain.
The domain follows a pattern previously associated with ShinyHunters activity. ReliaQuest has documented campaigns in which domains using a targeted company's name or abbreviation alongside the ".claims" top-level domain were used to impersonate help-desk or IT personnel.
The technique is particularly relevant to the alleged McKesson attack because social engineering is increasingly being used to obtain legitimate employee credentials rather than deploying malware directly against an organization's infrastructure.
ReliaQuest recently documented an attempted attack against its own employees in which an attacker used a lookalike domain, impersonated a security employee and attempted to persuade staff to authenticate through a fraudulent SSO page. Additional security controls prevented the attacker from reaching business applications or customer information.
Health-ISAC has also warned healthcare organizations about an increase in ShinyHunters activity involving social engineering, identity compromise and subsequent access to cloud and SaaS platforms.
Its analysis describes an attack chain in which threat actors use vishing or help-desk manipulation to compromise identity-provider accounts before moving into connected services. Such access can allow attackers to retrieve large volumes of information through legitimate cloud applications.
Research from the Retail & Hospitality ISAC has further linked ShinyHunters to the abuse of OAuth relationships and SaaS applications. By operating through legitimate identities or application permissions, attackers can make unauthorized activity more difficult to distinguish from ordinary cloud usage.
The alleged McKesson intrusion has not been independently confirmed to have followed this entire sequence, but the claimed
[…]
Content was trimmed to protect the source. Please visit the original article for the full text.
Read the original article: