Healthcare Cyberattacks Hit Pacemaker Workflows and Patient Records — The Hospital Has Discovered Voice Phishing in Formalwear

Boston Scientific and McKesson have disclosed separate healthcare cybersecurity incidents, giving the week a particularly refined bouquet of medical anxiety, operational disruption, and patient data exposure. According to The Register, one incident is affecting remote monitoring setup for newly implanted cardiac devices, while the other involves claimed theft of massive quantities of patient data by ShinyHunters.

🤚 The Open-Palm Clinical Disruption

Boston Scientific said an ongoing cyberattack that began around August 25 affected certain on-premise systems and disrupted manufacturing, shipping, ordering, and some device-related workflows. The company said the intrusion did not affect its cloud-based systems and apps, and that it had seen no indication of unauthorized IT activity since August 25. It has hired CrowdStrike to assist with investigation and restoration.

The most delicate part is not the usual corporate sentence about “restoring affected functions,” though naturally that sentence is present and wearing a tasteful compliance blazer. It is that newly implanted cardiac rhythm management devices, except insertable cardiac monitors, cannot currently activate new remote monitoring communicators. Available device data will not be transmitted to remote patient management systems until the communicators can be activated.

For insertable cardiac monitors, Boston Scientific said the devices can still record episodes, but new devices cannot pair with the patient remote monitoring mobile app until the service is restored. In-person transmission through the company’s Clinic Assistant app remains an option. This is reassuring in the way a chandelier remaining attached by one screw is technically reassuring: the room has not collapsed, but perhaps we should stop dancing directly beneath it.

👐 The Two-Handed Patient-Data Decanter

Meanwhile, McKesson confirmed unauthorized access to certain third-party applications and exfiltration of some data tied to a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units. The company said distribution centers remain operational and that it has “reasonable assurance” the intruders are no longer in the third-party environments or McKesson systems.

ShinyHunters told The Register it compromised more than 284 million patient-data records and demanded $55.2 million. That figure, like all criminal auction-house numerology, deserves caution. The Register also cited Have I Been Pwned’s Troy Hunt, who recently warned people not to treat criminals’ headline numbers as gospel unless the counting process is trustworthy. A ransomware gang’s spreadsheet is not exactly audited by a committee of nervous accountants in linen suits.

The claimed stolen data includes names, addresses, phone numbers, birth dates, Social Security numbers, appointment information, notes, illness details, and doctor-patient emails. McKesson has not publicly confirmed the exact number of affected people or the full data types involved. That distinction matters, because precision is what separates incident response from panic dressed as analytics.

🌿 The Gentle Awakening

The alleged initial access method is painfully familiar: ShinyHunters says it used voice phishing against multiple employees to access McKesson’s Snowflake and Salesforce instances. The group has used similar social-engineering tactics in other data-theft campaigns, because apparently the future of cybercrime is still calling a human being and sounding confident enough.

This is the great humiliation of modern cybersecurity. Healthcare organizations can buy threat intelligence feeds, endpoint tools, zero-trust architecture, cloud security dashboards, and entire conference sponsorship packages shaped like neon hexagons. Then someone with a telephone persuades an employee to do the thing. The palace has biometric gates, but the valet still accepts “trust me, I’m from IT” as a form of identification.

Healthcare is especially brittle because downtime is not merely an inconvenience. Delayed shipments, interrupted monitoring workflows, exposed oncology data, and patient communications are not abstract entries in a risk register. They are people’s bodies, diagnoses, appointments, treatments, anxieties, and family phone calls—converted by attackers into leverage and by companies into statements with carefully measured verbs.

👑 The Gold-Leaf Reckoning

The Boston Scientific and McKesson incidents are separate, but together they show the same uncomfortable dependency: medicine now rests on software systems, identity controls, SaaS platforms, logistics networks, mobile apps, remote monitoring, and vendors upon vendors, all stacked like champagne coupes at a charity gala. When one layer wobbles, everyone discovers exactly how much “clinical continuity” depends on ordinary IT not having a terrible Tuesday.

The lesson is neither exotic nor optional. Hospitals, device makers, distributors, and clinics need stronger identity verification, hardened third-party access, practiced downtime procedures, segmented systems, phishing-resistant authentication, and communication plans that do not require victims to decode corporate fog. They also need to treat voice phishing as a first-class threat, not a quaint relic from the era when attackers wore hoodies instead of customer-service voices.

Cybersecurity in healthcare is not a luxury control. It is part of care delivery. If the industry cannot protect the digital paths around patients, the attackers will continue finding ways to monetize illness with the vulgar efficiency of a concierge desk in hell.

“Please hold while your cardiac telemetry is transferred to our incident-response sommelier.” — The Slap of Wisdom Department of Clinical Champagne, disinfecting the threat model