news.mlab.sh
Back to the feed
threat-intel

Healthcare cyberattacks hit pacemakers and millions of patient records

High
Summary

Two major healthcare companies, Boston Scientific and McKesson, have been hit by separate cyberattacks resulting in significant disruptions and stolen patient data. Boston Scientific’s devices are currently unable to transmit remote monitoring data due to a hack affecting their medical devices, while McKesson confirmed a breach by the ShinyHunters group, who stole millions of patient records and demanded $55.2 million in ransom. The attack on McKesson involved voice phishing to gain access to their Snowflake and Salesforce systems.

Two major healthcare businesses, Boston Scientific and McKesson, have been hit by separate cyberattacks resulting in significant disruptions and stolen patient data.

Boston Scientific, a medical-device maker, disclosed that its IT systems were hacked by unknown intruders last week, and as a result, new remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated. This applies to all new cardiac rhythm management implants other than insertable cardiac monitors (ICM). ICM devices must be activated using the Boston Scientific Clinic Assistant app to ensure the device correctly records patients’ heart rhythms. The company does not have a timeline for full restoration. Boston Scientific has hired CrowdStrike to assist with the investigation and restoration efforts, and said the attack did not affect its cloud-based systems and apps - just “certain on-premise systems”.

Meanwhile, McKesson, a pharmaceutical and medical supply giant, confirmed an intrusion after ShinyHunters on Friday told The Register it broke into the company’s Snowflake and Salesforce instances and stole millions of patients’ data. “Based on our investigation thus far, including assessments by leading cybersecurity industry experts supporting our response, we’ve confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units,” Francisco Fraga, McKesson executive VP, chief information officer and chief technology officer, said in a Saturday statement. McKesson supports about 3,300 oncology providers in 29 states.

A ShinyHunters spokesperson told us that the notorious extortion group compromised more than 284 million records of patient data, and demanded McKesson pay $55.2 million or else they would leak the stolen data. The spokesperson claimed they accessed the company’s Snowflake and Salesforce instances by voice phishing “multiple employees.” The stolen data includes patients’ full names, home and email addresses, phone numbers, dates of birth, Social Security numbers, appointment dates and notes, and sensitive illness details including cancer locations on people’s bodies. The group also claims to have swiped emails containing private information from doctors to patients.

McKesson distribution centers remain operational and McKesson continues to ship products. The firm has “reasonable assurance” that the digital intruders have been kicked out of the third-party environments and aren’t lurking around McKesson’s systems.

Read the full article at The Register