Cybersecurity

McKesson Confirms Breach, Hackers Claim 284M Records

Published 1 min readBy NewUJ Editorial Desk

Updated new information added

McKesson Confirms Breach, Hackers Claim 284M Records
Photo: NewUJ
0 0
XWhatsAppTelegramLinkedIn

McKesson Corporation, one of the largest healthcare and pharmaceutical distributors in the US, said it is investigating a cybersecurity incident after the extortion group ShinyHunters claimed to have stolen a massive trove of patient data. The company disclosed the breach in a filing with the U.S. Securities and Exchange Commission on August 28, 2026, three days after discovering it.

According to security researchers, the attackers gained access using a voice-phishing (vishing) scheme, impersonating McKesson's IT help desk through a fraudulent domain, "mckesson[.]claims," to trick employees into handing over credentials for the company's Okta single sign-on system. That access allegedly let the group pull roughly 1 terabyte of data from McKesson's Salesforce and Snowflake environments between August 21 and 25.

ShinyHunters says the stolen records total about 284 million lines — the group has cautioned this is a raw count of data entries rather than unique patients — and include names, addresses, dates of birth, Social Security numbers, patient and Medicaid ID numbers, diagnoses, medications, allergies, appointment details, and physician information, alongside employee records.

The group demanded $55,236,150 within 72 hours to avoid publishing the files, a deadline McKesson did not meet. "McKesson is in the early stages of investigating a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data," the company said, adding that it has activated its incident response protocols and engaged outside cybersecurity experts. McKesson said it has not yet determined whether the incident is material to its financial results.

ShinyHunters has been linked to a string of large-scale breaches this year targeting companies that rely on Salesforce and Snowflake cloud platforms, including recent attacks on Manchester Airports Group and clothing retailer Carhartt.

Sources

Report / request removal

Related

Comments

No comments yet. Be the first.