ShinyHunters expose 6.4M in attack on medical supplier McKesson

https://image.theregister.com/230190.jpg?imageId=230190&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683

Have I Been Pwned logs leaked records spanning patients, staff, and providers

McKesson's cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP).

The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time.

ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply company in August, although HIBP did not confirm that figure.

The cybercriminals told The Register that they issued a $55.2 million extortion demand to prevent the release of McKesson's data – a sum that apparently was not paid, given the subsequent publication of the data.

HIBP said: "The impacted data related to a range of individuals and roles, including marketing campaign recipients, patients, staff, and healthcare provider contacts."

The types of information exposed vary between individuals, but the records collectively include names, email and physical addresses,...

Copyright of this story solely belongs to www.theregister.com. To see the full text click HERE