McKesson Hit by ShinyHunters: 284 Million Patient Data Records Claimed in Healthcare Breach
Healthcare and pharmaceutical distribution giant **McKesson** has disclosed a cybersecurity incident, with the notorious **ShinyHunters** extortion group claiming responsibility for stealing approximately 284 million patient data records. The breach, which involved unauthorized access to third-party applications and data exfiltration, highlights the increasing vulnerability of the healthcare sector to sophisticated social engineering attacks.

**McKesson**, a major U.S. healthcare company and pharmaceutical distributor, has confirmed a cybersecurity incident following reports of a significant data breach. The incident came to light after **CyberInsider** first reported the breach, subsequently confirmed by **McKesson** in a Form 8-K filing with the U.S. Securities and Exchange Commission.
### Incident Discovery and Initial Response
**McKesson** stated it discovered the cybersecurity incident on August 25, 2026. The company's investigation is still in its nascent stages, with updates available on its website. In its SEC filing, **McKesson** noted that it has not yet determined the incident to be material or to have a significant impact on its financial condition or operations.
In a separate notice to its customers, **McKesson** confirmed that the incident involved unauthorized access to third-party applications and the exfiltration of data. "Upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to assist in our response," the company's notice read.
While the investigation is ongoing, **McKesson** has warned that customers might experience intermittent service degradation believed to be related to the attack. The company has not proactively disconnected systems within its environment.
### ShinyHunters Claims Responsibility Through Vishing Attacks
The **ShinyHunters** extortion group has claimed responsibility for the attack, informing BleepingComputer that they gained access through voice phishing, or vishing, social engineering attacks targeting multiple **McKesson** employees.
The group reportedly used the `mckesson[.]claims` domain as part of their social engineering campaign. This aligns with a broader **ShinyHunters** tactic documented by **ReliaQuest**, where the group registers `.claims` domains impersonating help desks or IT teams of targeted companies.
### Compromise of Cloud Environments and Data Exfiltration
**ShinyHunters** stated that the vishing attacks led to the compromise of multiple employees' **Okta** single sign-on accounts. These compromised credentials were then used to access **McKesson**'s **Salesforce** and **Snowflake** environments.
The threat actor claims to have fully compromised the **Salesforce** environment, including support cases. More significantly, they allege the exfiltration of approximately 1TB of patient-related data from **Snowflake** over four days, from August 21 to August 25.
### Scope of Stolen Data
**ShinyHunters** clarified that the figure of 284 million refers to data records, or lines, rather than unique individuals, as the data has not been fully analyzed. The group claims the stolen information includes a wide array of sensitive data:
* Names, addresses, dates of birth
* Social Security numbers, patient IDs
* Phone numbers, email addresses, Medicaid numbers, medical record numbers
* Medication and allergy information, illnesses, disabilities, appointment information, and physician information
* Information related to deceased and terminally ill patients, prescriptions, medication shipments, and invoices
* Employee information, **Salesforce** records, internal communications, and details of healthcare providers and clinics using **McKesson**'s services.
These claims have not been independently verified by BleepingComputer, and **McKesson** has yet to publicly disclose the specific types of information stolen.
### Ransom Demand and Broader Campaign
**ShinyHunters** claims to have demanded a $55,236,150 ransom from **McKesson** after completing the data theft, giving the company 72 hours to respond. According to the group, **McKesson** did not engage in negotiations.
This attack is part of an ongoing wave of data-theft incidents attributed to **ShinyHunters** targeting the healthcare and health technology sectors. **Health-ISAC** recently issued a warning to healthcare organizations about the increasing number of **ShinyHunters** attacks, which often involve social engineering to compromise corporate accounts and gain access to cloud and SaaS platforms. Other notable healthcare organizations reportedly targeted by **ShinyHunters** include **Medtronic**, **DentaQuest**, **iRhythm**, **OneMedical**, and **AdaptHealth**.