On August 28, 2024, McKesson, a major pharmaceutical distributor, confirmed unauthorized access to certain third-party applications and data exfiltration affecting its Oncology & Multispecialty and Medical-Surgical business units. The hacker group ShinyHunters claimed responsibility, demanding a ransom after reportedly using social engineering to gain initial access.
Breach Timeline
August 28, 2024: McKesson announced an investigation into unauthorized access involving third-party applications and warned customers of potential service disruptions.
August 29, 2024: McKesson confirmed the breach, stating it affected certain third-party applications and data for some customers. They assured no ongoing unauthorized activity in their corporate network.
Post-disclosure: ShinyHunters claimed to have compromised records and demanded ransom. Reports suggest social engineering tactics were used against employees to gain initial access.
Identifying Control Failures
Third-Party Access Management: The breach indicates inadequate segmentation between third-party applications and sensitive data. Your team should ensure third-party access is strictly controlled and monitored.
Identity and Access Controls: If social engineering was used, gaps in multi-factor authentication (MFA) and privileged access management likely existed. Ensure attackers can't move from compromised credentials to sensitive environments.
Vendor Security Assessments: The incident highlights the need for continuous monitoring of third-party security postures. Annual assessments aren't enough to catch configuration changes or new vulnerabilities.
Data Exfiltration Detection: The breach suggests missing or ineffective data loss prevention controls. Implement robust monitoring for unusual data movements between your systems and vendor environments.
Security Awareness Training: Social engineering succeeded, indicating your security awareness program needs improvement. Ensure training covers specific tactics used by attackers and that employees can apply it in real scenarios.
Standards and Requirements
NIST Cybersecurity Framework (Supply Chain Risk Management, ID.SC-2 and ID.SC-3): Identify and assess suppliers and third-party partners, establishing security requirements and conducting ongoing assessments.
HIPAA Security Rule (45 CFR § 164.308(b)(1) and § 164.314(a)(2)(i)): Business associate agreements must include provisions for third parties to implement safeguards. Verify compliance to protect health information.
SOC 2 Trust Services Criteria (CC6.6 and CC6.7): Implement logical access security measures and define security measures for vendor systems.
ISO 27001:2022 (Controls 5.19 through 5.23): Define and document information security requirements for supplier access to your assets.
HITRUST CSF (10.j Outsourced Software Development): Include security requirements in third-party application development and monitor compliance.
Actionable Steps for Your Team
Continuous Vendor Security Monitoring: Deploy continuous monitoring using security ratings services. Require vendors to share security metrics quarterly to catch vulnerabilities quickly.
Enforce Least-Privilege Access: Map every API connection and service account. Limit access to only what's necessary. For example, a marketing vendor shouldn't access customer health records.
Segment Third-Party Environments: Use network segmentation to prevent attackers from accessing core data repositories if a third-party application is compromised.
Deploy Behavioral Analytics: Implement user and entity behavior analytics (UEBA) to detect unusual data access patterns in third-party applications.
Update Security Awareness Training: Train employees on specific social engineering tactics used in healthcare supply chains. Test retention with unannounced simulations.
Validate Vendor Attestations: Obtain and review SOC 2 Type II reports, ISO 27001 certificates, and HITRUST certifications. Ensure they cover the services you use.
Prepare Incident Response for Vendor Breaches: Update your Incident Response Structure to include scenarios where breaches start in vendor systems. Define communication protocols and criteria for terminating vendor access.
Establish Vendor Breach Notification Requirements: Require vendors to notify you within 24 hours of unauthorized access. Define reportable incidents and the information vendors must provide.
The McKesson incident highlights the critical need for robust third-party risk management in healthcare supply chains. Your team must actively manage these risks to protect your organization.





