Code Defence Cyber security

McKesson confirms customer data exfiltration following third party application breach

Healthcare supply chain maintainers have issued public incident updates confirming data theft following unauthorized access to integrated third-party applications. Threat actors systematically accessed external software integrations to extract sensitive customer records across enterprise medical supply divisions.

The security incident impacts McKesson Oncology and Multispecialty alongside Medical-Surgical operations. Incident response investigations confirmed that threat actors accessed compromised third-party application credentials to query backend databases and exfiltrate customer records. Extortion group ShinyHunters publicly claimed responsibility for the breach. While internal security teams report reasonable assurance that unauthorized access has been severed, forensic teams are analyzing exfiltrated data files to assess individual notification requirements.

Subverting third-party SaaS integrations exposes core enterprise data repositories without requiring direct perimeter breaches. When external software integrations hold over-permissioned API tokens or static administrative credentials, an unmonitored vendor compromise allows threat actors to bypass boundary firewalls and siphon sensitive customer vaults.

– Audit all third-party application integrations and OAuth permissions connected to corporate cloud environments immediately.

– Enforce mandatory multi-factor authentication and IP-restricted API gateways across all supply chain partner portals.

– Inspect application access logs for anomalous database query routines originating from external API integration tokens.

– Rotate administrative service account secrets and API keys associated with external healthcare management software.

Enterprise SaaS ecosystem security relies on strict non-human identity governance and continuous API query auditing to ensure external software integrations cannot be subverted into data exfiltration channels. #CodeDefence #McKesson #HealthcareSecurity #DataExfiltration #ThirdPartyRisk #AppSec #API #ShinyHunters
/

Scroll to Top