Boston Scientific, McKesson hit by separate healthcare cyberattacks

Two major healthcare businesses disclosed cyberattacks over the same weekend. Boston Scientific, a medical-device manufacturer, confirmed that an ongoing breach has disrupted remote monitoring for its pacemakers and other heart devices. The attack began on August 25 and hit the company's on-premise systems, though not its cloud-based platforms. The company said new remote monitoring communicators cannot be activated, so device data will not reach remote patient management systems until a communicator is activated. Manufacturing, shipping and ordering operations were also disrupted. Boston Scientific hired CrowdStrike to investigate and restore its systems, has not given a timeline for full recovery, and said it is working to partially restore shipping of some products this week.
Separately, pharmaceutical and medical supply giant McKesson confirmed an intrusion after the criminal group ShinyHunters claimed responsibility. McKesson said the breach involved unauthorized access to certain third-party applications affecting its Oncology & Multispecialty and Medical-Surgical business units. ShinyHunters says it got in through voice phishing targeting multiple McKesson employees, which gave it access to the company's Snowflake and Salesforce instances. The group claims to have taken more than 284 million patient records, including names, addresses, phone numbers, dates of birth, Social Security numbers, appointment information and sensitive medical details such as cancer locations, and it demanded $55.2 million or threatened to leak the data. Security experts caution against taking those figures at face value, noting that criminal groups routinely exaggerate the scope of what they have stolen. The two incidents were disclosed together but nothing in the reporting ties the Boston Scientific breach to the same attackers as the McKesson one.
Key facts
- Boston Scientific's ongoing breach, which began August 25, has disrupted remote monitoring for pacemakers and other heart devices, plus manufacturing, shipping and ordering.
- Boston Scientific hired CrowdStrike for investigation and restoration and has not given a recovery timeline, though it expects partial shipping restoration this week.
- McKesson confirmed an intrusion after ShinyHunters claimed it accessed the company's Snowflake and Salesforce instances via voice phishing.
- ShinyHunters claims to hold over 284 million patient records and demanded $55.2 million, but security experts say criminal groups often exaggerate breach scope.
- The stolen McKesson data allegedly includes names, addresses, Social Security numbers and sensitive medical details, affecting its Oncology & Multispecialty and Medical-Surgical units.
Why it matters
Two large healthcare-sector companies were hit by cyberattacks in the same weekend, and one of them, Boston Scientific, involves medical devices implanted in patients rather than just back-office data. A breach that stops remote monitoring communicators from activating means device data is not reaching the systems doctors and care teams use to watch a patient's heart remotely, which is a direct patient-safety concern rather than a purely administrative one.
Who it affects
Patients relying on Boston Scientific's remote monitoring for pacemakers and other heart devices are affected while new communicators cannot be activated. McKesson's Oncology & Multispecialty and Medical-Surgical business units were the ones affected by the unauthorized access, which puts patients and providers in those units at risk if the data ShinyHunters claims to hold, including Social Security numbers and cancer-related details, is genuine.
How to use it
Boston Scientific said it is working to partially restore shipping of some products this week, but has given no timeline for restoring remote monitoring or full operations, so affected patients and providers depend on further updates from the company rather than a fixed date. McKesson has confirmed the intrusion itself but has not said whether it will pay the ransom ShinyHunters demanded.
How solid is it
The breaches themselves are confirmed directly by both companies, including Boston Scientific's August 25 start date and its on-premise-only scope, and McKesson's statement about unauthorized access to third-party applications. The headline numbers, the 284 million records and the $55.2 million ransom, come only from ShinyHunters' own claims, and the reporting explicitly notes that security experts caution against accepting such claims at face value because criminal groups often exaggerate breach scope.
Risks and caveats
The scale of the McKesson breach is unverified: ShinyHunters is the sole source for both the record count and the ransom figure, and gangs have an incentive to inflate both to pressure payment. Nothing in the reporting confirms whether McKesson intends to pay, whether any patient has been harmed by the Boston Scientific monitoring disruption, or whether the two attacks are connected.
“New remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated.”
— Boston Scientific, company statement