Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.
McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies.
CyberInsider first reported the breach earlier today, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission.
McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation remains in the early stages.
“Information about the incident, including any updates, is available on the company’s website at www.mckesson.com/cybersecurity,” McKesson said in its SEC filing.
“As of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations.”
In a separate notice to customers, McKesson confirmed that the incident involved third-party applications and the unauthorized access and exfiltration of data.
“We take the security and privacy of our partners, customers and their patients very seriously. Upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to assist in our response,” reads McKesson’s notice.
The company said its investigation is ongoing to determine the full scope of the incident.
McKesson also warned that customers may experience intermittent service degradation believed to be related to the attack, although the company said it was not proactively disconnecting systems within its environment.
At this time, McKesson has not publicly disclosed which third-party applications were compromised, how the attackers gained access, or what information was stolen.
McKesson says its investigation remains ongoing and that it will provide additional information as it develops a more complete understanding of the incident.
ShinyHunters claims responsibility
The ShinyHunters extortion group told BleepingComputer that it was behind the attack, claiming it gained access after conducting voice phishing, or vishing, social engineering attacks against multiple McKesson employees.
ShinyHunters declined to provide many technical details about the social engineering attacks, including the domain used during the campaign. However, BleepingComputer learned from another source that the threat actors used the mckesson[.]claims domain as part of the attack.
This domain matches a ShinyHunters campaign recently documented by ReliaQuest’s Threat Research team, which said the extortion group was registering .claims domains containing the names or abbreviations of targeted companies to impersonate their help desks and IT teams.
“ReliaQuest is tracking a widespread ShinyHunters campaign using domains that follow the company[.]claims pattern. These domains incorporate the targeted organization’s name or abbreviation under the .claims TLD,” ReliaQuest said in a now-deleted post on X.
ShinyHunters told BleepingComputer that the vishing attacks led to the compromise of multiple employees’ Okta single sign-on accounts, which they then used to access the company’s Salesforce and Snowflake environments.
The threat actor claims it fully compromised the Salesforce environment, including support cases. The threat actor also allegedly stole a much larger collection of patient-related data from Snowflake.
According to ShinyHunters, the threat actor exfiltrated about 1TB of data over four days, between August 21 and August 25.
The threat actor also claims the stolen Snowflake data contains approximately 284 million data records of patient-related information. However, this does not mean that the breach impacted 284 million patients.
Previous reporting stated that information belonging to 284 million patients had been exposed. ShinyHunters clarified to BleepingComputer that the figure is actually a raw count of approximately 284 million data records, or lines, rather than a count of unique individuals.
The threat actor told BleepingComputer that it has not fully analyzed the stolen data and does not know how many unique people are in those records.
ShinyHunters claims the stolen information includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information, and physician information.
The group also claims the data contains information related to deceased and terminally ill patients, prescriptions and medication shipments, invoices, employee information, Salesforce records, internal communications, and healthcare providers and clinics using McKesson’s services.
BleepingComputer has not independently verified these claims, and McKesson has not publicly disclosed what information was stolen.
The group says it contacted McKesson after completing the data theft on August 25 and demanded a $55,236,150 ransom, giving the company 72 hours to respond. According to ShinyHunters, McKesson did not respond to or negotiate over the ransom demand.
The attack comes amid an ongoing wave of data-theft attacks targeting healthcare and health technology organizations attributed to ShinyHunters.
Health-ISAC recently warned healthcare organizations about increasing ShinyHunters attacks involving social engineering designed to compromise corporate accounts and gain access to cloud and SaaS platforms.
Other healthcare technology companies targeted in recent ShinyHunters data-theft attacks include Medtronic, DentaQuest, iRhythm, OneMedical, and AdaptHealth.
Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report
You must be logged in to post a comment Login