McKesson discloses breach after ShinyHunters claims patient data theft

McKesson headquarters

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with extortion group ShinyHunters claiming to have stolen 284 million patient data records.

McKesson is a major American healthcare company and pharmaceutical distributor that supplies drugs, medical supplies, technology and services to healthcare providers and pharmacies.

CyberInsider first reported the breach earlier today and McKesson later disclosed it in a Form 8-K filing with the US Securities and Exchange Commission.

image

McKesson says it discovered the cybersecurity incident on Aug. 25, 2026, and that the investigation remains in the early stages.

“Incident information, including any updates, is available on the company’s website at www.mckesson.com/cybersecurity,” McKesson said in his SEC Filing.

“As of the date of this filing, the company has not determined that the incident is material or that the incident has had or is reasonably likely to have any material effect on the company, including its financial condition or results of operations.”

In a separate notice to customers, McKesson confirmed that the incident involved third-party applications and unauthorized access and data theft.

“We take the security and privacy of our partners, customers and their patients very seriously. Upon discovery, we immediately activated our incident response protocols, launched an investigation and engaged leading cybersecurity industry experts to assist in our response,” it reads McKesson’s notice.

The company said the investigation is ongoing to determine the full extent of the incident.

McKesson also warned that customers may experience intermittent service degradation believed to be related to the attack, although the company said it is not proactively shutting down systems in its environment.

At this time, McKesson has not publicly disclosed which third-party applications were compromised, how the attackers gained access, or what information was stolen.

McKesson says its investigation is ongoing and that it will provide additional information as it develops a more complete understanding of the incident.

ShinyHunters takes responsibility

Extortion group ShinyHunters told BleepingComputer it was behind the attack, claiming it gained access after conducting voice phishing or social engineering attacks against multiple McKesson employees.

ShinyHunters declined to provide many technical details about the social engineering attacks, including the domain used during the campaign. However, BleepingComputer learned from another source that the threats used mckesson(.)says domain as part of the attack.

This domain matches a ShinyHunters campaign recently documented by The ReliaQuest Threat Research Teamwho said the extortion group registered .claims domains containing the names or abbreviations of the targeted companies to impersonate their help desks and IT teams.

“ReliaQuest tracked a widespread ShinyHunters campaign using domains that followed the company(.)claims pattern. These domains included the target organization’s name or abbreviation under the .claims TLD,” ReliaQuest said in a now-deleted X post.

ShinyHunters told BleepingComputer that the vishing attacks led to the compromise of multiple employees’ Okta single sign-on accounts, which they then used to access the company’s Salesforce and Snowflake environments.

The threat actor claims to have completely compromised the Salesforce environment, including support cases. The threat actor is also said to have stolen a much larger collection of patient-related data from Snowflake.

According to ShinyHunters, the threat exfiltrated about 1TB of data in four days, between August 21 and August 25.

The threat actor also claimed that the stolen Snowflake data contained approximately 284 million records of patient-related information. However, this does not mean that the breach affected 284 million patients.

Previous reports indicated that information belonging to 284 million patients was exposed. ShinyHunters clarified to BleepingComputer that the figure is actually a raw count of approximately 284 million data records or rows, not a count of unique individuals.

The threat actor told BleepingComputer that he hasn’t fully analyzed the stolen data and doesn’t know how many unique people are in those records.

ShinyHunters claims the stolen information includes names, addresses, dates of birth, social security numbers, patient identification numbers, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information and physician information.

The group also claims the data contains information related to deceased and terminally ill patients, prescriptions and drug shipments, invoices, employee information, Salesforce records, internal communications, and health care providers and clinics using McKesson’s services.

BleepingComputer has not independently verified these claims, and McKesson has not publicly disclosed what information was stolen.

The group claims to have contacted McKesson after committing the data theft on August 25 and demanded a ransom of $55,236,150, giving the company 72 hours to respond. According to ShinyHunters, McKesson has not responded to or negotiated the ransom demand.

The attack comes amid an ongoing wave of data theft attacks targeting healthcare and health technology organizations attributed to ShinyHunters.

Health-ISAC recently warned healthcare organizations about ShinyHunters’ growing attacks involving social engineering designed to compromise corporate accounts and gain access to cloud and SaaS platforms.

Other healthcare technology companies targeted in recent ShinyHunters data theft attacks include Medtronic, DentaQuest, iRhythm, OneMedical and AdaptHealth.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *