McKesson, one of the largest U.S. distributors of pharmaceuticals, medical supplies and healthcare technology, has confirmed that hackers accessed several cloud-hosted accounts and exfiltrated data, according to TechCrunch. The company said in a website statement Friday that it expected “intermittent service degradation” tied to the incident. TechCrunch reports that a separate customer notice from McKesson chief technology officer Francisco Fraga said the stolen data relates to the company’s oncology & multispecialty and medical-surgical units. The Texas-based company serves hospitals and healthcare providers across the United States and, according to TechCrunch, handles a large amount of patient data. The hacking group ShinyHunters told TechCrunch it was responsible. According to the report, the group said it gained access by tricking several McKesson employees into granting access through phishing and social-engineering tactics. The most sensitive details are still based on the attackers’ account. ShinyHunters told TechCrunch it stole personal information including names, addresses and Social Security numbers, as well as protected health information including diagnoses, medications, allergies and patient notes. The group also claimed it took millions of rows of patient data from McKesson’s cloud-hosted Snowflake and Salesforce environments, though it said it did not know how many individuals were ultimately affected. TechCrunch said ShinyHunters shared screenshots and a sample of the alleged stolen data, and that the outlet verified a small subset against public records. The report also says employee information, including home addresses, was among the stolen data. The ransom demand is separately attributed. TechCrunch cites Bleeping Computer as first reporting the connection to ShinyHunters and says the hackers demanded $55 million from McKesson in exchange for not publicly releasing the files. McKesson did not respond to TechCrunch’s request for comment Monday. The company has confirmed account compromise and data exfiltration, but the number of affected individuals, the full data set involved and the status of any ransom demand remain unresolved from the provided reporting. TechCrunch frames the incident as part of a broader run of attacks on healthcare companies and medical device makers. The report cites recent cyber incidents affecting Boston Scientific, Stryker, Abbott Laboratories, Medtronic, CareCloud and TriZetto, and says ShinyHunters has also taken credit for breaches at Amazon-owned OneMedical and DentaQuest. Who benefits: Extortion crews benefit when stolen health data creates pressure on healthcare companies to prevent publication. If ShinyHunters’ claims are accurate, the group may have leverage because the alleged data includes both personal identifiers and protected health information. Who's exposed: McKesson, its healthcare customers, affected patients and some employees are exposed until the company clarifies the scope. The highest-risk categories reported are Social Security numbers, diagnoses, medications, allergies, patient notes and home addresses.