Back to all lessons
Awareness Lessons
last month

McKesson Breach Exposes 284M Records in ShinyHunters Extortion Attack

McKesson, a major healthcare company, suffered a significant data breach in which attackers exfiltrated up to 284 million records containing personally identifiable information (PII), protected health information (PHI), and medical data. The ShinyHunters group's ability to access such a vast volume of sensitive records suggests inadequate access controls, insufficient data segmentation, or weak monitoring around critical data repositories. Healthcare organizations are high-value targets precisely because they hold large concentrations of sensitive data with regulatory value and personal harm potential. This incident underscores that even large enterprises with mature security programs can suffer catastrophic data loss if internal controls around sensitive data are not rigorously enforced. The ransom demand of $55 million reflects both the sensitivity of healthcare data and the growing boldness of extortion-focused threat actors.

Tactical Insight

Immediate actions

  • Conduct an urgent audit of all access permissions to systems storing PII and PHI, revoking any unnecessary or overprivileged accounts.
  • Implement data loss prevention (DLP) controls to detect and block large-scale exfiltration of sensitive records in real time.
  • Notify affected individuals promptly and engage law enforcement and forensic experts to scope the full extent of the breach.

Long-term improvements

  • Enforce strict data minimization principles so that no single system or database aggregates more sensitive records than operationally necessary.
  • Apply network segmentation and micro-segmentation to isolate systems containing PHI/PII from general corporate networks.
  • Establish and regularly test a formal incident response plan that includes ransomware and extortion-specific playbooks.

Detection measures

  • Deploy user and entity behavior analytics (UEBA) to flag anomalous bulk data access or export activity across healthcare data systems.
  • Maintain centralized, tamper-resistant logging of all access to sensitive data stores with alerting thresholds for high-volume queries.
  • Conduct regular third-party penetration testing and red team exercises focused on data exfiltration scenarios.