Boston Scientific and McKesson Both Found Out on August 25. We Scored Boston Scientific Clean in May. Then 53, Then 35. A Security Posture Is a Timestamp, Not a Property.
- Patrick Duggan
- 6 hours ago
- 10 min read
Two of the largest healthcare companies in America discovered they had been breached on the same day. Boston Scientific became aware of unauthorized activity on August 25 and disclosed a global operational disruption on August 26. McKesson discovered its incident on August 25 and confirmed the theft after ShinyHunters claimed it. Same day, different attack, same sector.
We have been publishing on this sector for five and a half months, and the honest accounting includes a call we got badly wrong about one of these two companies. Both belong in the same post.
What Actually Happened
Boston Scientific filed an 8-K with the SEC and said the incident prevented access to certain operating systems and business applications, affecting its ability to process and ship customer orders. The disruption is global. Employees at the manufacturing facility in Cork, Ireland were sent home because they could not work. Reporting has since described cardiac device supply to hospitals being stalled. The company says the unauthorized activity is limited to on-premise systems, that cloud-based systems and applications are unaffected, and that it has engaged third-party incident responders. No group has publicly claimed it as of this writing.
McKesson is a different animal entirely. ShinyHunters claims it used voice phishing against multiple McKesson employees to compromise their Okta single sign-on accounts, then pivoted into Salesforce and Snowflake and exfiltrated data. The group initially claimed 284 million patient records, then clarified that the figure refers to roughly 284 million database rows associated with an unknown number of people. That distinction matters and we are going to hold the line on it: rows are not people, and a number that large almost always shrinks when somebody counts humans instead of table entries. ShinyHunters says it demanded $55,236,150 with a 72-hour deadline and that McKesson did not negotiate.
The Part Where We Were Right
On March 15 we published a post whose thesis was the title: the medical device companies invisible to AI are the ones getting breached. That was five and a half months before Boston Scientific.
On July 16 we published the follow-up, and we did not write it as a victory lap. The title said we caught two and missed two, and the post laid out the sector map with the misses in it. Medtronic, Stryker, Intuitive Surgical and UFP had by then all proven the thesis in one direction or another. Boston Scientific is now the fifth.
On April 27 we published the attack chain, four months before McKesson. The description then was a help desk receiving a phone call from someone claiming to be an employee, the caller asking for an MFA reset on the employee's Okta single sign-on, the help desk obliging, and the attacker walking into Salesforce and exporting the customer file. On April 30 we tied the cluster together: Mandiant tags the actor UNC6040, the leak-site brand is ShinyHunters, one cluster.
On July 31, twenty-five days before McKesson, we published that ShinyHunters had stopped stealing vendor tokens and started making phone calls, and that Health-ISAC had warned its members of a rise in successful ShinyHunters attacks against healthcare and medical technology organizations. That was not our observation alone. Health-ISAC saw it independently and we said so at the time.
The McKesson chain as described this week is vishing into Okta into Salesforce. That is the chain we documented in April and the vertical pivot we documented in July, and we are claiming exactly that and nothing more. We did not name McKesson. Our named watch list on May 8 had eight names on it and McKesson was not one of them, and the window we gave was four to twelve weeks, which has since passed. Owning the mechanism is a real claim. Owning the victim would be a false one.
Clean Has a Shelf Life
On May 2 we published a post called "We Predicted Medtronic. The Receipts." In it we used Boston Scientific as a clean control. The exact words were that Boston Scientific and Intuitive Surgical were clean, with disciplined surface and low dev/test exposure and no breach.
That sentence contained two calls and they failed in two completely different ways, which is worth separating because only one of them is about decay.
On Boston Scientific the reading was correct on May 2. It was 115 days before the Cork plant went home, and in between, the number moved.
On Intuitive Surgical it was simply wrong when we wrote it. They had been breached on March 13, seven weeks earlier, through phishing into internal business applications. We called them clean in May because we had not noticed, and we said so in the July sector map: that is a miss, and it is our wheelhouse. No amount of talk about shelf life covers that one. We just did not know.
This is the part people get wrong about posture, and we wrote the sentence badly enough to get it wrong ourselves. A posture score is a timestamp, not a property. Boston Scientific was clean in the same way a blood pressure reading is normal: on the day you took it. We then wrote that two hours of analysis had "pre-validated what their CISOs had been doing for years," which is a permanent-sounding claim about a point-in-time measurement, and that phrasing is the thing we would take back. The measurement was fine. The tense was wrong.
We have published our own re-ranks before. On May 10 we put out "Cushman & Wakefield Broke Our Salesforce-Okta Filter. None of the Predicted Ten Have Hit. Re-Rank Inside," because a shop that only maps its wins is selling a brochure.
But this is not that. This is not a filter that was too narrow. This is a company that measured clean, drifted, and had nobody re-taking the measurement — including us, because they were never a consumer of anything we produce. We scored them the way we score any domain on request: once, from the outside, into the void. Our own May 2 post said the quiet part already, about a different company: customers get this comparison continuously, and Medtronic got the snapshot once, on March 19, at the top of an email they did not reply to. Boston Scientific got a snapshot too.
And then the harder truth, which is the one worth carrying out of this post.
You can be good and get got. That is the game.
A clean posture is not a shield and was never sold as one. Boston Scientific may well have been running a genuinely disciplined program on August 24 and been taken on August 25 anyway, and nothing in our data would contradict that. McKesson had a proper RFC 9116 disclosure channel scoring 92 and got taken by somebody phoning a help desk. Good posture lowers your odds; it does not buy you an exemption, and any vendor telling you otherwise is selling a certificate rather than a defense.
Which is exactly why the artifact that matters is not the grade. It is whether anybody is still watching after the grade is issued.
The Minnesota Corridor
This is a Minnesota story and that is not a coincidence of geography.
Medtronic's operational heart is in Fridley. Boston Scientific's cardiac rhythm management business runs out of Arden Hills and Maple Grove. Abbott's cardiac device business is the old St. Jude Medical in Little Canada. Those three campuses employ thousands of people within an hour's drive of each other, and they are the anchors of the medical device corridor.
Two of the three anchors have now been breached inside five months.
So we ran the third one, along with the rest of the sector, through our own AI Presence Monitor. Every number below is ours, produced by the same public instrument anybody can run for free at aipmsec.com. The AIPM combined score runs to 95. The security.txt column scores whether an outside researcher can reach you at all, on the rubric we published on May 8 when we added it as the eighth technical signal.
Boston Scientific, Arden Hills and Maple Grove, combined score 35, security.txt 0, breached August 25. Their trend is the part worth reading: 65 on April 1, 48 on April 12, 53 on June 23, and 35 when we re-ran it this week after the breach.
Medtronic, Fridley, combined score 54 as of June 23, breached in April.
Abbott, the old St. Jude Medical in Little Canada, combined score 18, security.txt 0, not breached. That is the lowest score in the corridor and the lowest we have recorded in this sector.
McKesson, combined score 48, security.txt 92, breached August 25.
Intuitive Surgical, combined score 51, security.txt 15, breached on March 13 through phishing into internal business applications. We did not cover it at the time and said so in July.
Baxter, combined score 34 with a structure score of 2, no breach but with patient-facing infrastructure we have flagged before.
Stryker, 52 on June 23 and 34 on August 21.
Read That Table Honestly, Because It Does Not Say What You Want It To Say
McKesson scores 92 on security.txt. That is a proper RFC 9116 file with a valid contact directive. They can receive a vulnerability report. They got breached anyway, and the reason is the whole point: a security.txt does nothing against a phone call to a help desk. Vishing does not arrive through your disclosure channel. It arrives through a human being who wants to be helpful.
So security.txt is not a breach predictor and we are not going to pretend it is. It is a warnability signal. It tells you whether an outsider who spots something can tell you before it costs you. Boston Scientific scores 0 and Abbott scores 0, which means that for those two, an outside researcher who found something had no documented way in.
The combined score does not sort this sector either, and the cleanest way to show that is to point at the worst number on our own list. Abbott scores 18. That is the lowest reading we have ever recorded in medical devices, it comes with a security.txt of 0, and Abbott has not been breached. Meanwhile Boston Scientific sat at 53 in June and Intuitive Surgical at 51, and both of them were breached this year. If the score were a ranking of who gets hit, Abbott would have gone first and did not.
So we will say it plainly rather than let a chart imply otherwise: our own data does not support the claim that a low AI presence score predicts a breach at the company level. Anyone selling you a single number that sorts a sector is selling something.
What the data does support is narrower. The sector call has held five times over five and a half months, and sector calls are the honest unit here because the mechanism is shared: phishing and phone calls into companies that make devices hospitals cannot stop using. The legibility score tells you how well an outsider — a customer, a researcher, an AI model answering a question about you — can see you. The security.txt sub-score tells you whether that outsider can reach you. Neither is armor. Both are cheap, and one of them is why Boston Scientific and Abbott are companies a researcher cannot warn.
The Series Is the Product, Not the Score
Boston Scientific reads 65 on April 1, 48 on April 12, 53 on June 23, and 35 this week. That is not a clean slide — it dips, recovers a little, and then drops hard after the breach, and the last reading is measuring a company in the middle of an incident, so treat it as an effect rather than a warning.
The four readings before and around it are the interesting part, and the honest statement about them is small: a mid-fifties number that had been a sixty-five is a change worth a phone call, and nobody made one. Not their monitoring, because a company does not usually watch its own AI legibility. Not ours, because they were not a customer and we had already filed them under clean.
That is the whole product argument and we would rather state it plainly than dress it up. A single audit is a photograph. Anyone can take one, ours is free, and it will tell you something true about the day you took it. What it cannot do is notice that the number moved, because noticing requires somebody to still be looking in September at what they measured in April.
We are not going to claim that a subscription would have stopped this. Nothing in our data supports that and the McKesson chain says the opposite — a phone call to a help desk does not care what any score says. What continuous measurement buys you is narrower and duller and real: you find out that something changed while it is still cheap to ask why.
If You Work in This Corridor
Publish a security.txt. It is thirty minutes and zero dollars, RFC 9116 has been a standard since April 2022, and two of the three anchor companies in the Minnesota medical device corridor still do not have one. That fixes warnability, not breach risk, and it is still the cheapest thing on this list.
Then go look at your help desk. Every documented ShinyHunters intrusion this year has run through a human being on a phone granting an MFA reset. The control is a callback procedure and an out-of-band verification step, not a product. McKesson had the good disclosure channel and it did not matter, because nobody attacked the channel.
And if you run any kind of continuous measurement on your own organization, go read the trend rather than the current value. We did not, and the company we called clean is the reason this post exists.
Sources and Credit
Reporting on Boston Scientific from TechCrunch, The Register, CBS News, Cybersecurity Dive and HIPAA Journal, plus Boston Scientific's own incident statement and 8-K. Reporting on McKesson from BleepingComputer, Help Net Security, CyberInsider and DataBreaches.net. The UNC6040 attribution is Mandiant's. The healthcare targeting warning that preceded McKesson by weeks was Health-ISAC's, issued to its members, and we cited it at the end of July rather than claiming it.
Our own posts referenced above are dated March 15, April 27, April 30, May 2, May 8, May 10, July 16 and July 31, and every one of them is on this site including the two that record our misses.
We cap our confidence at 95 percent as a matter of policy. Something in here is wrong; it usually is. If you find it, there is a security.txt at analytics.dugganusa.com and it works.
Run your own domain through aipmsec.com. It is free, it takes about fifteen seconds, and it will tell you your security.txt score before somebody else finds out for you.
Every indicator in this post is in the feed. Free.
1.58M+ IOCs, STIX 2.1 / TAXII, 88% novel vs ThreatFox, exploited-CVE leads ahead of CISA. No credit card — a free API key in 30 seconds, and you can audit every claim above against the live endpoints.
Was this useful? Thirty seconds, no cookies, no tracking, no third parties, your address hashed and never stored. If the box below does not load, the same question lives at https://analytics.dugganusa.com/nps.html?post=boston-scientific-and-mckesson-both-found-out-on-august-25-we-scored-boston-scientific-clean-in-may




Comments