McKesson Confirms Breach, Hackers Claim 284M Records

McKesson Corporation, one of the largest healthcare and pharmaceutical distributors in the US, said it is investigating a cybersecurity incident after the extortion group ShinyHunters claimed to have stolen a massive trove of patient data. The company disclosed the breach in a filing with the U.S. Securities and Exchange Commission on August 28, 2026, three days after discovering it.
According to security researchers, the attackers gained access using a voice-phishing (vishing) scheme, impersonating McKesson's IT help desk through a fraudulent domain, "mckesson[.]claims," to trick employees into handing over credentials for the company's Okta single sign-on system. That access allegedly let the group pull roughly 1 terabyte of data from McKesson's Salesforce and Snowflake environments between August 21 and 25.
ShinyHunters says the stolen records total about 284 million lines — the group has cautioned this is a raw count of data entries rather than unique patients — and include names, addresses, dates of birth, Social Security numbers, patient and Medicaid ID numbers, diagnoses, medications, allergies, appointment details, and physician information, alongside employee records.
The group demanded $55,236,150 within 72 hours to avoid publishing the files, a deadline McKesson did not meet. "McKesson is in the early stages of investigating a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data," the company said, adding that it has activated its incident response protocols and engaged outside cybersecurity experts. McKesson said it has not yet determined whether the incident is material to its financial results.
ShinyHunters has been linked to a string of large-scale breaches this year targeting companies that rely on Salesforce and Snowflake cloud platforms, including recent attacks on Manchester Airports Group and clothing retailer Carhartt.
Sources
- McKesson (SEC Form 8-K)Primary source
- BleepingComputerSecondary
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- Two New Islands Rise by Anak Krakatau After 25-Hour Eruption
- New Gut Bacterium C. immunis Cut Visceral Fat in Obese Mice
- Meta's 100-Gram VR Glasses Cost $1,299.99, Ship Spring 2027
- Kurihara, 11, One Win From Youngest Asian Games Medal
- Yu Zidi, 13, Wins Third Asian Games Gold in 4:28.56 400 IM
- Haaland Passes Ronaldo and Zlatan With 64th Norway Goal
- Claude Leads 26% of Anthropic's AI R&D, Up From 1% in March
- SEC Grants 5-Year Exemption for Tokenized Stock Trading
Comments
No comments yet. Be the first.