Skip to Content
Join the Network with Us — Join Membership


McKesson Discloses Cyberattack as ShinyHunters Claims 28 Crore Data Records Stolen

August 29, 2026

McKesson has disclosed a cybersecurity incident involving unauthorised access to third-party applications and the theft of data, while the ShinyHunters extortion group has claimed responsibility, saying it exfiltrated about 284 million patient-related data records.

The Incident and Its Disclosure

The U.S. healthcare and pharmaceutical distribution company said it discovered the incident on August 25, 2026. Its investigation remains at an early stage, and McKesson hasn't publicly disclosed which third-party applications were compromised, how attackers gained access, or exactly what information was taken.

The company disclosed the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission, stating it had not yet determined whether the incident was material or reasonably likely to have a material impact on its financial condition or results of operations.

What McKesson Has Confirmed So Far

McKesson confirmed that the incident involved third-party applications and the unauthorised access and exfiltration of data. The company said it activated incident response protocols after discovering the breach, launched an investigation, and engaged cybersecurity specialists to assist with the response.

Customers were warned they could experience intermittent service degradation believed to be connected to the attack. McKesson said it wasn't proactively disconnecting systems within its environment, and that its investigation is continuing to determine the full scope of the incident, with more information to follow as understanding develops.

ShinyHunters' Claims: A Voice-Phishing Attack

ShinyHunters claimed it gained access after conducting voice-phishing, or vishing, attacks against multiple McKesson employees. According to the group, these attacks led to the compromise of several employees' Okta single sign-on accounts, which were then allegedly used to access the company's Salesforce and Snowflake environments. The group said approximately 1TB of data was exfiltrated over four days, between August 21 and August 25.

ShinyHunters said the stolen Snowflake data contained about 284 million patient-related data records, though it clarified this figure represents a raw count of records rather than 284 million unique patients, adding that it hadn't yet determined how many individuals were actually represented in the dataset.

What the Group Claims Was Stolen

ShinyHunters claims the stolen information includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information, and physician details.

The group also claimed the data includes information relating to deceased and terminally ill patients, prescriptions, medication shipments, invoices, employee information, Salesforce records, internal communications, and details of healthcare providers and clinics using McKesson's services. It's important to note that these claims have not been independently verified, and McKesson has not publicly confirmed what information was actually stolen.

ShinyHunters further claimed it demanded a ransom of $55,236,150 after completing the data theft on August 25, giving McKesson 72 hours to respond. The group said the company did not negotiate over the demand.

Part of a Larger Pattern Targeting Healthcare

This incident comes amid a broader wave of data-theft attacks targeting healthcare and health technology organisations, with warnings issued about social-engineering campaigns specifically aimed at compromising corporate accounts and gaining access to cloud and SaaS platforms, a pattern that mirrors similar attacks seen across other industries in recent months.

FAQs

Q1. How did ShinyHunters claim to have gained access to McKesson's systems?

The group claimed it conducted voice-phishing attacks against McKesson employees to compromise their Okta single sign-on accounts, which were then used to access the company's Salesforce and Snowflake environments.

Q2. How much data was allegedly stolen, and what did it contain?

ShinyHunters claimed to have exfiltrated approximately 1TB of data over four days, containing about 284 million patient-related data records, including names, Social Security numbers, medical information, and prescription details.

Q3. Has McKesson confirmed the details claimed by ShinyHunters?

No, McKesson has not publicly confirmed what specific information was stolen, and the group's claims regarding the scope and content of the breach have not been independently verified.

in News
Share this post
Archive