ShinyHunters хакеруудын бүлэг фишинг болон сошиал инженерийн арга ашиглан АНУ-ын эрүүл мэндийн салбарын томоохон төлөөлөгч McKesson компанийн үүлэн орчинд нэвтэрч, эмзэг мэдээллийг хулгайлснаа зарлалаа
АНУ-ын Техас мужид төвтэй, эм болон эмнэлгийн хэрэгсэл түгээлтийн салбарт тэргүүлэгч McKesson компани өнгөрсөн долоо хоногт кибер халдлагад өртсөнөө баталлаа. Тус компанийн технологи хариуцсан захирал Франциско Фрагагийн мэдээлснээр, хакерууд компанийн үүлэн тооцооллын орчинд нэвтэрч, онкологи болон эмнэлгийн мэс заслын нэгжийн үйл ажиллагаатай холбоотой өгөгдлүүдэд зөвшөөрөлгүй хандалт хийсэн байна. Энэхүү үйл явдлын улмаас компанийн үйлчилгээнд түр зуурын доголдол үүсээд байгаа аж.
ShinyHunters хэмээх хакеруудын бүлэг фишинг болон сошиал инженерийн аргаар ажилтнуудыг хууран мэхэлж, компанийн сүлжээнд нэвтэрсэн гэдгээ мэдэгдлээ. Тэд Snowflake болон Salesforce үүлэн орчноос өвчтөнүүдийн овог нэр, хаяг, нийгмийн даатгалын дугаар, онош, хэрэглэдэг эм, харшил болон бусад эмнэлгийн тэмдэглэл бүхий сая сая мөрийн өгөгдлийг хулгайлсан байна. Мөн тус компанийн ажилтнуудын хувийн мэдээлэл ч алдагдсан байх магадлалтай байна.
Эх сурвалжуудын мэдээлснээр, хакерууд хулгайлсан мэдээллийг олон нийтэд задруулахгүй байхын тулд 55 сая ам.долларын барьцаа нэхэмжилжээ. McKesson компани халдлагын улмаас хичнээн хүн хохирсныг одоогоор тодорхойлоогүй байгаа бөгөөд асуудалтай холбоотой дэлгэрэнгүй тайлбар өгөхөөс татгалзсан байна.
Сүүлийн саруудад эрүүл мэндийн салбарын компаниуд кибер халдлагын бай болж байгаа нь эрчимжиж байна. Тухайлбал, Boston Scientific, Stryker, Abbott Laboratories, Medtronic зэрэг байгууллагууд халдлагад өртсөн бол CareCloud болон TriZetto компаниуд тус бүр 3 сая гаруй өвчтөний мэдээллийг алдсан тохиолдол гарчээ.
Дэлгэрэнгүйг эх сурвалжаас харах
↓Эх сурвалжийг нээх ↓
A prolific hacking group has taken credit for last week’s cyberattack against U.S. pharmaceutical distribution giant McKesson, leading to the latest spill of highly sensitive health data by an American healthcare company in recent months.
McKesson confirmed Friday in a statement on its website that hackers broke into several of its cloud-hosted accounts earlier in the week and exfiltrated data, and that the company expected “intermittent service degradation” related to the incident. In a separate notice to customers, the company’s chief technology officer, Francisco Fraga, said the stolen data relates to its oncology & multispecialty and medical-surgical units.
The Texas-based company is one of the largest American distributors of pharmaceuticals, medicines, medical supplies, and technology to hospitals and healthcare providers across the United States, and as such handles a large amount of patient data.
The ShinyHunters hacking group — one of the most active data-extortion crews of the past two years — told TechCrunch that it hacked the company’s cloud environment by tricking several employees into granting the hackers’ access to McKesson’s network by using phishing and social engineering tricks, which the group is known for.
The hackers said they stole a range of personal information, such as names, addresses, and Social Security numbers, as well as protected health information, including diagnoses, medications, allergies, and patient notes. The hackers say they took millions of rows of patient data from the company’s cloud-hosted Snowflake and Salesforce environments, but that they are unsure of how many individuals are ultimately affected.
The stolen data also included McKesson employees’ information, such as home addresses.
ShinyHunters shared screenshots and a sample of the stolen data with TechCrunch, and we verified a small subset of it against public records.
Bleeping Computer, which first reported the link to the ShinyHunters hacking group, said the hackers demanded a $55 million ransom from the company in exchange for not publicly releasing the stolen files.
A spokesperson for McKesson did not respond to TechCrunch’s request for comment on Monday.
McKesson is the latest healthcare company or medical device maker to be targeted in a string of cyberattacks in recent months, as hackers aim to steal large amounts of sensitive medical and health data that they can use to extort the companies into paying a ransom to keep it from being published.
Last week, medical device maker Boston Scientific was hit by a cyberattack that knocked much of the company’s network offline. The cyberattack had a similar effect to an incident earlier this year at another medical device maker Stryker, in which hackers abused a company’s internal tools to remotely wipe thousands of employee devices. Abbott Laboratories and Medtronic have also experienced cyberattacks, while electronic patient records provider CareCloud and health tech company TriZetto had breaches affecting over 3 million patients each.
The ShinyHunters hackers have also taken credit for sizable data breaches at Amazon-owned OneMedical and dental insurance company DentaQuest following cyberattacks on their systems.
Lorenzo Franceschi-Bicchierai contributed reporting.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

