
Data Security News Update
Real Breaches. Real Impact. Stay Informed
284 Million Rows in Four Days: McKesson's Cloud Warehouses Emptied
- BIG DEAL
McKesson, which moves about a third of America’s prescription medicines, told the SEC on 28 August that attackers had reached third-party applications and taken data. ShinyHunters claims 284 million records pulled from the company’s Snowflake and Salesforce environments between 21 and 25 August, covering tens of millions of patients: names, Social Security numbers, diagnoses, medications, Medicaid identifiers and doctor-patient messages. The group demanded US$55.2 million and says McKesson never replied. The figure counts rows rather than people, and McKesson has confirmed none of it. What it has confirmed is enough: patient records sat readable in rented cloud warehouses, and anyone holding a working login could copy them.
- TAKEAWAY A cloud data warehouse gathers everything worth stealing in one place. Encrypt the sensitive columns before they land there, hold the keys outside the platform, and rehearse the answer to a 72-hour ultimatum before one arrives.


Half a Nation's Medical Records: Poland's MyDr Breach Reaches 19 Million People
- BIG DEAL
Poland’s Digital Affairs Minister confirmed on 12 August that attackers had taken more than 2.5 terabytes from MyDr, the electronic medical records supplier used by some 12,000 clinics, covering almost 19 million people, close to half the population. The haul spans PESEL national identity numbers, prescriptions, appointments, medications and documents patients handed to their doctors; the intruders sent journalists a screenshot of a senior politician’s file to prove it. The stolen material was historical data held through April 2024, kept long after the consultations it recorded had ended. The privacy regulator UODO has opened an inspection, and the government has warned that clinics themselves may face GDPR penalties.
- TAKEAWAY Data retained past its purpose is a liability waiting for a buyer. Set retention rules that actually delete, encrypt whatever archive remains, and treat a supplier's database as your own exposure, because the regulator will.

