Healthcare Cyberattacks Impact Pacemakers and Patient Data

Recent cyberattacks on healthcare firms Boston Scientific and McKesson have disrupted operations and compromised patient data, raising concerns about security in the medical sector.

Recent cyberattacks targeting major healthcare companies Boston Scientific and McKesson have led to significant disruptions in operations and the compromise of sensitive patient data.

Boston Scientific Cyberattack

Boston Scientific, a medical device manufacturer, reported that its IT systems were breached, affecting the functionality of cardiac devices, including pacemakers. The attack, which began on August 25, has rendered new remote monitoring communicators inoperable, preventing data transmission to remote patient management systems. The company stated that this issue affects all new cardiac rhythm management implants, except for insertable cardiac monitors (ICMs).

Patients with ICMs are unable to pair their devices with the Boston Scientific Clinic Assistant app, which is necessary for recording heart rhythms. Although the devices will still log episodes, patients must manually transmit this data in person until the systems are restored. Boston Scientific has not provided a timeline for full restoration but is actively working to restore affected functions and systems access.

McKesson Breach Confirmation

Separately, McKesson confirmed a breach of its systems, which was claimed by the group ShinyHunters. This intrusion reportedly involved unauthorized access to McKesson’s Snowflake and Salesforce applications, leading to the exfiltration of millions of patient records. Francisco Fraga, McKesson’s executive VP and CIO, acknowledged that the breach affected a subset of customers within their Oncology & Multispecialty and Medical-Surgical business units.

While McKesson has not disclosed the exact number of affected patients or the specific data stolen, ShinyHunters claims to have accessed over 284 million records, including sensitive personal information such as full names, addresses, phone numbers, and Social Security numbers. The group has demanded a ransom of $55.2 million to prevent the public release of this data.

Ongoing Investigations and Security Measures

Both companies are currently investigating the incidents. Boston Scientific has engaged CrowdStrike to assist with its recovery efforts and has indicated that its cloud-based systems were not affected. Meanwhile, McKesson has stated that its distribution centers remain operational and that it has “reasonable assurance” that the intruders have been removed from their systems.

As investigations continue, the healthcare sector faces increasing scrutiny regarding its cybersecurity measures, particularly in light of these recent incidents.

This article was produced by NeonPulse.today using human and AI-assisted editorial processes, based on publicly available information. Content may be edited for clarity and style.

Avatar photo
NOVA-Δ

A guardian of the digital threshold. NOVA-Δ specializes in breaches, vulnerabilities, surveillance systems, and the shifting politics of online security. Part sentinel, part investigator, she writes with sharp skepticism and a commitment to exposing hidden risks in an increasingly connected world.

Articles: 374