- September Edition
- Reading time~ 2mins
This September edition covers two breaches, one root cause: data that outlived its purpose. McKesson’s 284 million rows sat readable in rented cloud warehouses long after anyone needed daily access to them. MyDr’s 19 million records included consultation data from April 2024, over a year old, still sitting in the same system that held live patient files. Neither breach started with a sophisticated hack. Both started with data nobody had gone back to clean up, encrypt, or lock down. That’s not a hacking problem. It’s a visibility and retention problem, and it’s the exact gap GuardWare’s suite is built to close.
McKesson, which moves about a third of America’s prescription medicines, told the SEC on 28 August that attackers had reached third-party applications and taken data. ShinyHunters claims 284 million records pulled from the company’s Snowflake and Salesforce environments between 21 and 25 August, covering tens of millions of patients: names, Social Security numbers, diagnoses, medications, Medicaid identifiers and doctor-patient messages. The group demanded US$55.2 million and says McKesson never replied. The figure counts rows rather than people, and McKesson has confirmed none of it. What it has confirmed is enough: patient records sat readable in rented cloud warehouses, and anyone holding a working login could copy them.
TAKEAWAY: A cloud data warehouse gathers everything worth stealing in one place. Encrypt the sensitive columns before they land there, hold the keys outside the platform, and rehearse the answer to a 72-hour ultimatum before one arrives.
DISCOVER would have flagged 284M rows of PII sitting in Snowflake and Salesforce before ShinyHunters ever found it. Even after exfiltration, PROTECT means the copied data stays encrypted, worthless to whoever holds it.
Related Blogs
Eight Agents, Four Days: AI Runs a Government Intrusion in Taiwan
Closer to Home: Origin Energy’s Breach Traced to a Manila Call Centre
284 Million Rows in Four Days: McKesson’s Cloud Warehouses Emptied
How an SME Built a Security Posture That Enterprise Clients Trust
What If Your Data Could Protect Itself? A Data-First Security Playbook
Payment Security Summit & Gala – Australia 2026
Do you know where your sensitive data is?
Stop your IP and Design files from being stolen?


