Cybersecurity Sep 1, 2026Add to bookmarks

Cyberattacks have targeted pacemakers and exfiltrated millions of patient records in August 2026. The healthcare sector joins water and energy on the list of critical infrastructures regularly targeted.
In August 2026, McKesson—one of the world’s largest pharmaceutical distributors—acknowledged a major data breach. The ShinyHunters group claimed responsibility for the attack and demanded a $55.2 million ransom. Meanwhile, a wave of cyberattacks on healthcare facilities also targeted connected medical devices, including pacemakers. Healthcare is emerging as one of the new frontiers for cyberattacks on critical infrastructure.
McKesson directly—and by extension, healthcare facilities, pharmacies, and partners relying on its systems. More broadly, hospitals and clinics equipped with connected medical devices (IoMT—Internet of Medical Things): cardiac monitors, pacemakers, implantable defibrillators. Patients with these devices are directly exposed.
ShinyHunters is a well-documented group specializing in large-scale data theft: Tokopedia (91M accounts in 2020), AT&T (70M records in 2024), Ticketmaster (500M customers in 2024). Their modus operandi: exfiltrate data, then threaten to publish or sell it if the ransom isn’t paid.
With McKesson, potentially millions of patient records, medical data, and pharmaceutical supply chain details are exposed. The $55.2M demand reflects the estimated scale of the breach.
Connected medical devices suffer from vulnerabilities well-known to security researchers:
CISA warned in July 2026 about over 100 water systems affected and published a scathing report at the end of August on structural vulnerabilities in U.S. critical infrastructure. Healthcare is following the same path.
The attack on pacemakers moves beyond data theft to threaten the physical integrity of patients—a scenario long theorized by researchers (Billy Rios, IOActive) since the 2010s, now a documented reality in 2026.
Article produced by artificial intelligence, reviewed under human editorial control.
CISA et la résilience des infrastructures critiques américaines en 2026