Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the alleged theft of data. The ShinyHunters extortion group claims it stole approximately 284 million patient-related records from the company.
McKesson is a leading U.S. healthcare company and pharmaceutical distributor that provides pharmaceuticals, medical supplies, technology, and services to healthcare providers and pharmacies.
CyberInsider first reported the McKesson data breach. The company later disclosed the cybersecurity incident in a Form 8-K filing with the U.S. Securities and Exchange Commission.
McKesson said it discovered the cybersecurity incident on August 25, 2026, and that its investigation remains in the early stages.
“Information about this incident, including the latest information, is available on the company’s website at: www.mckesson.com/cybersecurity,” McKesson said in its SEC filing.
“As of the date of this filing, we have not determined that the incident is material or that the incident has had, or is reasonably likely to have, a material impact on our company, including our financial condition and results of operations.”
In a separate notice to customers, McKesson acknowledged that the incident involved unauthorized access to third-party applications and the exfiltration of data.
“We take the security and privacy of our partners, customers, and patients very seriously. Upon discovering the incident, we immediately activated our incident response protocols, began an investigation, and deployed leading cybersecurity industry experts to assist in the response,” the company said in a customer notice.
McKesson said the investigation is ongoing and will determine the full scope and impact of the incident.
The company also warned that customers may experience intermittent service degradation believed to be related to the attack. However, McKesson said it is not actively disconnecting systems within its environment.
McKesson has not disclosed which third-party applications were compromised, how the attackers gained access, or what information may have been stolen.
The company said it will provide additional information as its investigation progresses and more details become available.
ShinyHunters claims responsibility for McKesson attack
The ShinyHunters extortion group told BleepingComputer that it was behind the attack, claiming that it gained access after conducting voice phishing, or vishing, attacks against multiple McKesson employees.
ShinyHunters declined to provide technical details about the alleged social engineering campaign, including the domains used by the attackers. However, BleepingComputer learned from another source that the domain McKesson[.]claim was used as part of the attack.
The domain is consistent with a recently documented ShinyHunters campaign. According to the ReliaQuest Threat Research Team, the extortion group registered domains containing the names and abbreviations of targeted companies to impersonate help desks and IT departments.
“ReliaQuest is tracking a wide range of ShinyHunters campaigns using domains that follow the company.[.]claim pattern. These domains incorporate the targeted organization’s name or abbreviation in the .claims TLD,” ReliaQuest said in a now-deleted post on X.
ShinyHunters told BleepingComputer that the attack compromised the Okta single sign-on accounts of multiple McKesson employees. The accounts were allegedly used to access the company’s Salesforce and Snowflake environments.
The attackers claim to have fully compromised McKesson’s Salesforce environment, including support cases. They also allegedly stole a large volume of patient-related data from Snowflake.
According to ShinyHunters, the attackers exfiltrated approximately 1 TB of data over a four-day period from August 21 through August 25.
The group also claims that the stolen Snowflake data includes approximately 284 million patient-related records. However, this figure does not necessarily represent 284 million unique patients.
Earlier reports suggested that information belonging to 284 million patients had been compromised. ShinyHunters later clarified to BleepingComputer that the figure refers to the approximate number of raw data records, or rows, rather than the number of individual people.
The attackers said the stolen data had not been fully analyzed, making it unclear how many unique individuals are represented in the records.
ShinyHunters claims the information includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment details, and physician information.
The group also claims the data includes information about deceased and terminally ill patients, prescriptions and drug shipments, invoices, employee information, Salesforce records, internal communications, and healthcare providers and clinics that use McKesson’s services.
BleepingComputer has not independently verified these claims, and McKesson has not disclosed what information was stolen or accessed.
After completing the alleged data theft on August 25, ShinyHunters said it contacted McKesson and demanded a $55,236,150 ransom. The group reportedly gave the company 72 hours to respond. According to ShinyHunters, McKesson did not respond to the ransom demand or enter negotiations.
The alleged McKesson data breach comes amid a continuing wave of attacks targeting healthcare and medical technology organizations that have been attributed to ShinyHunters.
Health-ISAC recently warned healthcare organizations about an increase in socially engineered ShinyHunters attacks designed to compromise corporate accounts and gain access to cloud and software-as-a-service platforms.
Other healthcare technology companies targeted in recent ShinyHunters data theft attacks reportedly include Medtronic, DentaQuest, iRhythm, One Medical, and AdaptHealth.
The overall prevention score can hide what happens after initial access. If an attacker uses valid credentials, your defenses can drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




