Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack
A cyberattack is causing service issues for the pharmaceutical and healthcare technology company McKesson.
The company released a public notice and filed documents with the Securities and Exchange Commission (SEC) on Friday evening saying it is in the early stages of investigating a cybersecurity incident that involves an unnamed third-party application.
The hackers have gained access to the application and are exfiltrating data, McKesson said.
“At this time, customers may experience intermittent service degradation that we believe may be related to this incident,” McKesson chief technology officer Francisco Fraga said in a statement. “We are aware of these issues and continue to monitor the situation closely.”
In an update on Saturday, the company said the hackers exfiltrated data associated with customers in their oncology and surgical business units. Fraga said they will provide credit monitoring and identity protection services to customers whose data was exfiltrated.
They have also received “reasonable assurance” that the hackers are no longer inside McKesson systems.
“Customers can continue to connect to and use our systems and services as intended,” Fraga explained.
He noted that it is not proactively disconnecting systems — an action typically taken during ransomware attacks to limit the reach of attackers and contain the blast radius of the incident.
He urged customers to contact the company if there are technical issues with services. McKesson said it is still in the midst of an investigation and did not answer questions about the incident when reached for comment.
The ShinyHunters cybercriminal group took credit for the attack on Friday night, threatening the company with potential leaks in a post on their blog. The group has spent more than two years attacking and extorting some of the largest companies in the world.
Earlier this year, the FBI warned that hackers linked to ShinyHunters were demanding substantial ransom payments from companies after stealing data through compromises involving Salesforce environments.
The group caused chaos across the U.S. in May with an attack on a widely used educational software suite and stole the information of more than four million people after attacking the world’s largest medical device company in April.
Other victims include Carnival Cruises, Ticketmaster, AT&T, McGraw Hill and ADT and gaming company Rockstar.
McKesson reported $106 billion in revenue last quarter. About one-third of all prescriptions in North America are delivered by the company.
The Texas-based company distributes pharmaceuticals, produces drugs for oncology patients, and manufactures a range of critical medical-surgical supplies, laboratory equipment and more.
McKesson is the latest large healthcare company to be attacked this year after medical device giants Boston Scientific and Medtronic both reported cybersecurity incidents. Another large medical device firm, Stryker, was also hit with a cyberattack earlier this year.
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.



