```html ```
top of page

Boston Scientific and McKesson Both Found Out on August 25. We Named the Sector in March, the Chain in April, and Called Boston Scientific 'Clean' in May. The Whole Table, Misses Included.

  • Writer: Patrick Duggan
    Patrick Duggan
  • 6 hours ago
  • 7 min read

Two of the largest healthcare companies in America discovered they had been breached on the same day. Boston Scientific became aware of unauthorized activity on August 25 and disclosed a global operational disruption on August 26. McKesson discovered its incident on August 25 and confirmed the theft after ShinyHunters claimed it. Same day, different attack, same sector.


We have been publishing on this sector for five and a half months, and the honest accounting includes a call we got badly wrong about one of these two companies. Both belong in the same post.



What Actually Happened


Boston Scientific filed an 8-K with the SEC and said the incident prevented access to certain operating systems and business applications, affecting its ability to process and ship customer orders. The disruption is global. Employees at the manufacturing facility in Cork, Ireland were sent home because they could not work. Reporting has since described cardiac device supply to hospitals being stalled. The company says the unauthorized activity is limited to on-premise systems, that cloud-based systems and applications are unaffected, and that it has engaged third-party incident responders. No group has publicly claimed it as of this writing.


McKesson is a different animal entirely. ShinyHunters claims it used voice phishing against multiple McKesson employees to compromise their Okta single sign-on accounts, then pivoted into Salesforce and Snowflake and exfiltrated data. The group initially claimed 284 million patient records, then clarified that the figure refers to roughly 284 million database rows associated with an unknown number of people. That distinction matters and we are going to hold the line on it: rows are not people, and a number that large almost always shrinks when somebody counts humans instead of table entries. ShinyHunters says it demanded $55,236,150 with a 72-hour deadline and that McKesson did not negotiate.





The Part Where We Were Right


On March 15 we published a post whose thesis was the title: the medical device companies invisible to AI are the ones getting breached. That was five and a half months before Boston Scientific.


On July 16 we published the follow-up, and we did not write it as a victory lap. The title said we caught two and missed two, and the post laid out the sector map with the misses in it. Medtronic, Stryker, Intuitive Surgical and UFP had by then all proven the thesis in one direction or another. Boston Scientific is now the fifth.


On April 27 we published the attack chain, four months before McKesson. The description then was a help desk receiving a phone call from someone claiming to be an employee, the caller asking for an MFA reset on the employee's Okta single sign-on, the help desk obliging, and the attacker walking into Salesforce and exporting the customer file. On April 30 we tied the cluster together: Mandiant tags the actor UNC6040, the leak-site brand is ShinyHunters, one cluster.


On July 31, twenty-five days before McKesson, we published that ShinyHunters had stopped stealing vendor tokens and started making phone calls, and that Health-ISAC had warned its members of a rise in successful ShinyHunters attacks against healthcare and medical technology organizations. That was not our observation alone. Health-ISAC saw it independently and we said so at the time.


The McKesson chain as described this week is vishing into Okta into Salesforce. That is the chain we documented in April and the vertical pivot we documented in July, and we are claiming exactly that and nothing more. We did not name McKesson. Our named watch list on May 8 had eight names on it and McKesson was not one of them, and the window we gave was four to twelve weeks, which has since passed. Owning the mechanism is a real claim. Owning the victim would be a false one.



The Part Where We Were Wrong


On May 2 we published a post called "We Predicted Medtronic. The Receipts." In it we used Boston Scientific as a clean control. The exact words were that Boston Scientific and Intuitive Surgical were clean, with disciplined surface and low dev/test exposure and no breach, and that two hours of analysis had pre-validated what their CISOs had been doing for years.


That was 115 days before Boston Scientific sent its Cork plant home.


We have done this before and we published that too. On May 10 we put out a post titled "Cushman & Wakefield Broke Our Salesforce-Okta Filter. None of the Predicted Ten Have Hit. Re-Rank Inside." A shop that only maps its wins is selling a brochure. So: our attack-surface read on Boston Scientific said disciplined, and disciplined was not the same thing as safe, and we stated the stronger conclusion.



The Minnesota Corridor


This is a Minnesota story and that is not a coincidence of geography.


Medtronic's operational heart is in Fridley. Boston Scientific's cardiac rhythm management business runs out of Arden Hills and Maple Grove. Abbott's cardiac device business is the old St. Jude Medical in Little Canada. Those three campuses employ thousands of people within an hour's drive of each other, and they are the anchors of the medical device corridor.


Two of the three anchors have now been breached inside five months.


So we ran the third one, along with the rest of the sector, through our own AI Presence Monitor. Every number below is ours, produced by the same public instrument anybody can run for free at aipmsec.com. The AIPM combined score runs to 95. The security.txt column scores whether an outside researcher can reach you at all, on the rubric we published on May 8 when we added it as the eighth technical signal.


Boston Scientific, Arden Hills and Maple Grove, combined score 35, security.txt 0, breached August 25. Their trend is the part worth reading: 65 on April 1, 48 on April 12, 53 on June 23, and 35 when we re-ran it this week after the breach.


Medtronic, Fridley, combined score 54 as of June 23, breached in April.


Abbott, the old St. Jude Medical in Little Canada, combined score 18, security.txt 0, not breached. That is the lowest score in the corridor and the lowest we have recorded in this sector.


McKesson, combined score 48, security.txt 92, breached August 25.


Intuitive Surgical, combined score 51, security.txt 15, not breached.


Baxter, combined score 34 with a structure score of 2, no breach but with patient-facing infrastructure we have flagged before.


Stryker, 52 on June 23 and 34 on August 21.



Read That Table Honestly, Because It Does Not Say What You Want It To Say


McKesson scores 92 on security.txt. That is a proper RFC 9116 file with a valid contact directive. They can receive a vulnerability report. They got breached anyway, and the reason is the whole point: a security.txt does nothing against a phone call to a help desk. Vishing does not arrive through your disclosure channel. It arrives through a human being who wants to be helpful.


So security.txt is not a breach predictor and we are not going to pretend it is. It is a warnability signal. It tells you whether an outsider who spots something can tell you before it costs you. Boston Scientific scores 0 and Abbott scores 0, which means that for those two, an outside researcher who found something had no documented way in.


The combined score does not cleanly separate the breached from the unbreached either. Boston Scientific was 53 in June and Intuitive Surgical was 51, and one of them is now shipping cardiac devices by hand. Anyone who tells you a single number sorts this sector is selling something.


What the data does support is narrower and, we think, more useful. The sector call has held five times. Within the sector, the two lowest legibility scores we have on file belong to companies that could not be warned. And the one company that could be warned was taken by a method that ignores the warning channel entirely, which is exactly why we score eight signals instead of one.



The Trend Is the Signal, Not the Score


Boston Scientific went 65, 48, 53, 35. We watched a number fall by nearly half across five months and we did not write about it, because we had already published them as a clean control and nobody goes looking for reasons they were wrong.


That is the actual lesson of this post and it is aimed at us before anybody else. We built an instrument that takes a reading every time we point it at a domain, we pointed it at this company four times, and the readings went down every time we looked. A declining series on a company you have publicly called clean is the highest-value alert your own system can generate, and we treated it as noise.


The tooling was not broken. Nobody was reading it.



If You Work in This Corridor


Publish a security.txt. It is thirty minutes and zero dollars, RFC 9116 has been a standard since April 2022, and two of the three anchor companies in the Minnesota medical device corridor still do not have one. That fixes warnability, not breach risk, and it is still the cheapest thing on this list.


Then go look at your help desk. Every documented ShinyHunters intrusion this year has run through a human being on a phone granting an MFA reset. The control is a callback procedure and an out-of-band verification step, not a product. McKesson had the good disclosure channel and it did not matter, because nobody attacked the channel.


And if you run any kind of continuous measurement on your own organization, go read the trend rather than the current value. We did not, and the company we called clean is the reason this post exists.



Sources and Credit


Reporting on Boston Scientific from TechCrunch, The Register, CBS News, Cybersecurity Dive and HIPAA Journal, plus Boston Scientific's own incident statement and 8-K. Reporting on McKesson from BleepingComputer, Help Net Security, CyberInsider and DataBreaches.net. The UNC6040 attribution is Mandiant's. The healthcare targeting warning that preceded McKesson by weeks was Health-ISAC's, issued to its members, and we cited it at the end of July rather than claiming it.


Our own posts referenced above are dated March 15, April 27, April 30, May 2, May 8, May 10, July 16 and July 31, and every one of them is on this site including the two that record our misses.


We cap our confidence at 95 percent as a matter of policy. Something in here is wrong; it usually is. If you find it, there is a security.txt at analytics.dugganusa.com and it works.


Run your own domain through aipmsec.com. It is free, it takes about fifteen seconds, and it will tell you your security.txt score before somebody else finds out for you.




Every indicator in this post is in the feed. Free.

1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.



Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=boston-scientific-and-mckesson-both-found-out-on-august-25-we-named-the-sector-in-march-the-chain



Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page