Two major healthcare businesses, Boston Scientific and McKesson, disclosed more details over the weekend about separate cyberattacks that disrupted global operations and resulted in stolen patient data, respectively. Medical-device maker Boston Scientific, whose IT systems were hacked by unknown intruders last week, said the cyberattack remains ongoing. It also noted that pacemakers and other heart devices implanted after the August 25 breach cannot provide remote monitoring and data transmission as intended. “New remote monitoring communicators cannot be activated, thus available device data will NOT be transmitted to remote patient management systems until the communicator can be activated,” the medtech firm said in a late Friday update. This applies to all new cardiac rhythm management implants other than insertable cardiac monitors (ICM). ICM devices must be activated using the Boston Scientific Clinic Assistant app to ensure the device correctly records patients’ heart rhythms, the company added. Because of the cyberattack, “new ICMs are unable to pair to the patient remote monitoring mobile phone, therefore available episode data recorded by the ICM will NOT be transmitted to the remote monitoring system until the ICM can be paired to the patient mobile app,” according to the update. The devices will still record any episodes, and patients can transmit these to the remote monitoring system by in-person transmission via the Clinic Assistant app. This is done by selecting the “interrogate” button, according to the company. Once its IT systems are back up and running, and the heart devices can pair with home monitoring equipment, they will again transmit recorded data to the remote systems. However, the company does not have a timeline for full restoration. “We are currently working on restoring affected functions and systems access,” Boston Scientific said on Saturday. The digital intrusion also affected the firm’s manufacturing, shipping, and ordering, it noted. “We are expeditiously working towards partial restoration for the shipping of some products this week,” according to a Sunday update. “Once we can demonstrate the restoration is fully operable, we anticipate ordering and shipping will ramp up to full capacity.” Boston Scientific has hired CrowdStrike to assist with the investigation and restoration efforts, and said the attack did not affect its cloud-based systems and apps - just “certain on-premise systems” - and added that it has seen no indication of unauthorized IT activity since August 25. The firm has repeatedly declined to answer The Register’s questions about the compromise, including whether it was a ransomware infection and which criminal crew is responsible. McKesson confirms breach as ShinyHunters claims responsibility Meanwhile, in another cybersecurity incident that has been very publicly claimed by the criminal perpetrator: pharmaceutical and medical supply giant McKesson over the weekend confirmed an intrusion after ShinyHunters on Friday told The Register it broke into the company’s Snowflake and Salesforce instances and stole millions of patients’ data. “Based on our investigation thus far, including assessments by leading cybersecurity industry experts supporting our response, we’ve confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units,” Francisco Fraga, McKesson executive VP, chief information officer and chief technology officer, said in a Saturday statement. The medical firm did not immediately respond to The Register’s questions, including how many patients were affected and what “certain data” was stolen. McKesson supports about 3,300 oncology providers in 29 states, according to its website. Fraga’s statement noted that distribution centers remain operational and McKesson continues to ship products. The firm has “reasonable assurance” that the digital intruders have been kicked out of the third-party environments and aren’t lurking around McKesson’s systems, he added. A ShinyHunters spokesperson told us that the notorious extortion group compromised more than 284 million records of patient data, and demanded McKesson pay $55.2 million or else they would leak the stolen data. However, as Have I Been Pwned boss Troy Hunt recently reminded everyone: Don’t confuse criminals’ claims with gospel truth, and “take headline numbers with a grain of salt unless you're confident in the processes of those making the claims." This was after Hunt’s HIBP service reported 12.9 million individuals affected by retailer Carhartt’s alleged breach. This number was around half of what ShinyHunters claimed when they leaked the company’s data earlier this month. The McKesson records, according to the ShinyHunters spokesperson, include patients’ full names, home and email addresses, phone numbers, dates of birth, Social Security numbers, appointment dates and notes, and sensitive illness details including cancer locations on people’s bodies. The group also claims to have swiped emails containing private information from doctors to patients. The spokesperson told us they accessed the company’s Snowflake and Salesforce instances by voice phishing “multiple employees.” This is a tried-and-true method popularized by the data-theft-and-extortion gang, which has victimized other medical providers in recent months. These include pacemaker manufacturer Medtronic in April, and cancer diagnostics business Exact Sciences in July. ®
CRPx0, a cybercrime crew that has rapidly evolved from a scam service to a ClickFix-delivered ransomware and crypto-theft business over the summer, claims its victim count jumped from fewer than 10 in June to 48 organizations on its clear-web leak site at the time of publication. Keep in mind: criminals aren’t always the most trustworthy bunch, so take their claims with a healthy dose of salt. Still, the ransomware biz’s expanding operations, unique payload, and white-label hacking service make it one to watch, and a few recent analyses provide tips for defenders to keep the crooks out of their IT environments. Rakesh Krishnan, a threat-intel analyst who writes about cybercrime investigations on TheRavenFile blog, was one of the first researchers to publish details about CRPx0 at the beginning of the month, including previously unreleased malware samples. The operators offer a hacking service, providing “complete database extraction” from victim organizations and “optional public leak coordination upon request.” This platform also advertises full network compromise, “from initial access, through lateral movement, to full domain compromise,” plus persistent access across the victim’s infrastructure. A second, white-label, ransomware-as-a-service platform makes it really easy for wannabe crooks to get into the data-theft and extortion biz. CRPx0 builds, deploys, and configures everything from command-and-control infrastructure to the negotiation panel and malware, allowing its criminal customers to bring their own brand identity to their operations - and originally offered these services for a $10,000 one-time fee. At first, the operators promised to allow affiliates to keep 100 percent of their profits - this is unheard of in ransomware-as-a-service operations. This has since shifted to a 70-30 model, with affiliates receiving 70 percent of the extortion payments (after a one-time $333 enrollment fee) and the remaining 30 percent going to the operators. CRPx0 rules prohibit affiliates from infecting Commonwealth of Independent States (CIS) member countries and organizations based in these countries. This is a pretty common rule among Russia-based ransomware operations, and in an earlier interview with The Register, Recorded Future threat intelligence analyst Allan Liska called it the “first rule of ransomware club: you don't attack organizations in the Commonwealth of Independent States.” The gang also prefers Monero (XMR) payments, rather than Bitcoin (BTC). ClickFix ransomware delivery Affiliates can also customize their own ClickFix payload delivery. The operators offer two lures, a fake Windows Update and a fake Google reCAPTCHA, to socially engineer victims into executing the initial command, according to a Ransom-ISAC research team analysis published on Thursday. The Windows lure tricks a victim into pasting a PowerShell command into the Run dialog. This drops a DLL stager chain and ultimately deploys Python-based ransomware. The macOS lure, however, uses a curl|bash command that downloads portable Python and the ransomware directly. The lures and the rest of CRPx0’s malware run on Windows and macOS, and according to the researchers, there are four payload formats: “the two HTML lures plus a standalone DLL and a standalone EXE, both of which discard the social engineering step entirely.” All four deliver the same ransomware: a 1,769-line Python script that steals high-value files before encrypting them with AES-128-CBC (Fernet). The malware moves laterally via WMI/schtasks, and delivers a ransom note that gives victims a 48-hour deadline to pay up - or see their files leaked. 'Complete, professional offensive control center' On August 23, the CRPx0 operators published a v3.0 update note on the group’s clearnet leak site, promising “a complete, professional offensive control center for managing compromised remote machines from a single web dashboard.” It provides crims with tools to steal valuable files, credentials, and wallet recovery phrases and keys, while “watching stolen cryptocurrency wallet addresses flow in.” This service also provides scripts to run remote commands, and the control panel sets up “automated attack reactions that fire on their own when something valuable happens on a target.” As the operators note: “Everything is built to be operated by a human with no technical background: point-and-click panels, plain-language rules, and clear status indicators. The underlying attack engine is hidden behind a clean, dark-themed interface.” CRPx0’s hacking and ransomware services, enabling everything from crypto theft to encryptors and full network compromise, “could be a strategic move to attract new recruits, or a scam targeting a range of affiliate hopefuls seeking cybercrime services,” according to an August 12 analysis from Jade Brown, a threat researcher at Bitdefender. What defenders should do Still, “other threat actors may attempt to adopt similar techniques,” she warns. “This is a reminder that organizations should balance detection capabilities in preparation for different types of compromises, configuring technologies to detect and block malicious behavior that aligns with both crypto theft and encryption processes.” The Ransomware-ISAC team says defenders should prioritize five actions, in this order. “The first three cost nothing and blunt the entire ClickFix class of attack, not just CRPx0,” they note. First: remove the Run dialog for standard users - this will entirely block the Windows path. For macOS users: restrict Terminal via MDM for non-technical staff. Next, the threat-intel analysts advise defenders to alert on RunMRU writes containing powershell, curl or long base64 strings. “Every ClickFix victim leaves a trace at HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU,” they wrote. “This is the highest-fidelity ClickFix detection available and it is trivial to deploy.” The team also lists adversary network indicators and suggests blocking those. Make sure to hunt for indicators and malicious behavior in the pre-encryption exfiltration window. “Data leaves before a single file is encrypted, so .crpx0 extensions and ransom notes are a post-mortem indicator, not a warning,” according to the Ransomware-ISAC. Finally, confirm backups are unreachable from the account that would be compromised, and treat anything reachable with the victim's credentials as destroyed. ®
The US government disclosed that crims targeted more than 100 internet-exposed water systems during July cyberattacks. That's the first time the feds have put a number on the digital intrusions, but they have yet to attribute the campaign, widely suspected to be linked to Iran, to a particular group. “In July 2026, CISA observed malicious cyber activity targeting over 100 internet-exposed systems in the Water and Wastewater Systems (WWS) Sector, commonly via programmable logic controllers (PLCs) connected directly to a cellular modem,” America’s lead cyber-defense agency said, adding that connecting PLCs directly to the internet “can create significant security risks.” Suspected Iranian attackers targeted water and wastewater facilities across at least a dozen states in July, including internet-exposed PLCs. While neither federal nor state officials have identified all 12, we know that the cyberattacks occurred at mostly small, rural utilities in Minnesota, Michigan, Georgia, South Dakota, and New Jersey. “This is very serious. What stands out isn't any single incident. It's the scale,” Matt Hartman, chief strategy officer at the Merlin Group and CISA’s former acting head of cyber, told The Register. “More than 100 water systems with internet-exposed assets were hit in a single month, which points to a systemic vulnerability across the sector, not a run of isolated, unlucky targets,” Hartman said. “Much of this infrastructure runs on operational technology that was built for closed, physical environments. It was never designed with the assumption that it would be reachable from the open internet.” John Gallagher, VP at Viakoo, an OT and IoT cybersecurity provider, told us that while 100 systems represent a small fraction - only about 0.5 percent - of water utilities in the US, the “real threat is that these are test runs for a larger-scale attack.” While the 100-plus water incidents occurred in July, just last week five US federal agencies warned that attackers are using AI-generated exploitation scripts to break into internet-exposed Siemens S7 Series PLCs at water, manufacturing, energy, and other critical facilities. “This appears to be a continuation of the same suite of activity we suspect is affiliated with Iran targeting PLCs,” Halcyon Ransomware Research Center SVP Cynthia Kaiser told The Register a week ago. “Iran-affiliated actors and adversaries are actively targeting a wide swath of operational technology because these PLCs underpin essential health, safety, and critical infrastructure across society,” Kaiser, a former FBI cyber division deputy assistant director, added. While third-party analysts have largely blamed Iran for the intrusions, the federal government has not attributed the attacks to anyone. “Attribution in cyber incidents is inherently difficult and often takes time. Adversaries deliberately obscure their infrastructure, reuse tools and techniques, and route activity through compromised systems, so the government needs to be diligent before publicly assigning responsibility,” Hartman said. “In this case, CISA has done the most important thing: quickly getting actionable information into the hands of water-sector operators so they can defend their systems,” he added. “From a defender’s perspective, the ‘who’ matters less in the immediate term than understanding how the attacks are occurring and taking steps to stop them.” In its advisory, CISA recommended organizations disconnect PLCs from the internet and ensure any remote access goes through a VPN or gateway device rather than connecting directly to the PLC. The cyber-defense agency also advised owner-operators to enable password protection (we suggest multi-factor authentication) and change any default passwords. Also: ensure that allowlist IPs only allow remote access from known engineering laptops or other critical OT assets.®