Skip to main content
McKessonSecurity incident

Healthcare cyberattacks hit pacemakers and millions of patient records

What happened

McKesson confirmed a data breach after the ShinyHunters group claimed to have stolen millions of patient records from its Snowflake and Salesforce instances and demanded a $55.2 million ransom.

Source

Article excerpt

Security McKesson admits breach as ShinyHunters demands $55.2M Two major healthcare businesses, Boston Scientific and McKesson, disclosed more details over the weekend about separate cyberattacks that disrupted global operations and resulted in stolen patient data, respectively. Medical-device maker Boston Scientific, whose IT systems were hacked by unknown intruders last week, said the cyberattack remains ongoing. It also noted that pacemakers and other heart devices implanted after the August 25 breach cannot provide remote monitoring and data transmission as intended. “New remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated,” the medtech firm said in a late Friday update. This applies to all new cardiac rhythm management implants other than insertable cardiac monitors (ICM). ICM devices must be activated using the Boston Scientific Clinic Assistant app to ensure the device correctly records patients’ heart rhythms, the company added. Because of the cyberattack, “new ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app,” according to the update. The devices will still...

Keep reading with a free account

The rest of this article, and every signal for McKesson, is in your free account.

Extracted from this sentence

Meanwhile, in another cybersecurity incident that has been very publicly claimed by the criminal perpetrator: pharmaceutical and medical supply giant McKesson over the weekend confirmed an intrusion after ShinyHunters on Friday told The Register it broke into the company’s Snowflake and Salesforce instances and stole millions of patients’ data.

Extracted by Autobound

From the Signal API record
Event
Security incident

What this signalsA breach often leads to new security spend.

Amount named
$55.2M

More security incident signals at other companies

The full record

From the Signal API record

Numbers

Amount named in the story
$55.2M

Details

Issue named
Intrusion into Snowflake and Salesforce instances resulting in exfiltration of patient data, with ShinyHunters demanding a $55.2M ransom.

Extraction

Confidence
100%
Detected
Aug 31, 2026
signal_type
news
signal_subtype
security_incident

Use this data

Get every security incident signal for McKesson and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at McKesson this week?”

  2. Send it to your own tools

    The Signal API returns security incident signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full news record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/ff3771b5-6e18-5232-a56d-43e2b76647c6 returns this record as JSON. POST /v1/companies/enrich returns every signal for mckesson.com.

{
  "signal_id": "ff3771b5-6e18-5232-a56d-43e2b76647c6",
  "signal_type": "news",
  "signal_subtype": "security_incident",
  "detected_at": "2026-08-31T22:10:38+00:00",
  "company": {
    "name": "McKesson",
    "domain": "mckesson.com"
  },
  "data": {
    "url": "https://www.theregister.com/cyber-crime/2026/08/31/healthcare-cyberattacks-hit-pacemakers-and-millions-of-patient-records/5293537",
    "title": "Healthcare cyberattacks hit pacemakers and millions of patient records",
    "excerpt": "Security McKesson admits breach as ShinyHunters demands $55.2M Two major healthcare businesses, Boston Scientific and McKesson, disclosed more details over the weekend about separate cyberattacks that disrupted global operations and resulted in stolen patient data, respectively. Medical-device maker Boston Scientific, whose IT systems were hacked by unknown intruders last week , said the cyberattack remains ongoing. It also noted that pacemakers and other heart devices implanted after the August 25 breach cannot provide remote monitoring and data transmission as intended. “New remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated,” the medtech firm said in a late Friday update. This applies to all new cardiac rhythm management implants other than insertable cardiac monitors (ICM). ICM devices must be activated using the Boston Scientific Clinic Assistant app to ensure the device correctly records patients’ heart rhythms, the company added. Because of the cyberattack, “new ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app,” according to the update. The devices will still...",
    "summary": "McKesson confirmed a data breach after the ShinyHunters group claimed to have stolen millions of patient records from its Snowflake and Salesforce instances and demanded a $55.2 million ransom.",
    "planning": false,
    "image_url": "https://image.theregister.com/259951.jpg?imageId=259951&x=0&y=0&cropw=100&croph=100&panox=0&panoy=0&panow=100&panoh=100&width=1200&height=683",
    "confidence": 1,
    "published_at": "2026-08-31T22:10:38Z",
    "vulnerability": "Intrusion into Snowflake and Salesforce instances resulting in exfiltration of patient data, with ShinyHunters demanding a $55.2M ransom.",
    "article_sentence": "Meanwhile, in another cybersecurity incident that has been very publicly claimed by the criminal perpetrator: pharmaceutical and medical supply giant McKesson over the weekend confirmed an intrusion after ShinyHunters on Friday told The Register it broke into the company’s Snowflake and Salesforce instances and stole millions of patients’ data.",
    "amount_normalized": 55200000
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.