McKesson, a major U.S. healthcare and pharmaceutical distribution company, has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration. The ShinyHunters extortion group has claimed responsibility for the attack, asserting that it stole approximately 284 million patient data records.
The company first detected the incident on August 25, 2026, and subsequently filed a Form 8-K with the U.S. Securities and Exchange Commission, confirming the breach. McKesson stated that its investigation is in its early stages and that it has not yet determined the incident's material impact on the company's financial condition or operations. Customers have been notified that the incident involved third-party applications and unauthorized data access, and the company is working with cybersecurity experts to understand the full scope. McKesson has also warned of potential intermittent service degradation for customers, which is believed to be related to the attack.
ShinyHunters informed a cybersecurity publication that they executed the attack through voice phishing, or vishing, social engineering tactics targeting multiple McKesson employees. While specific technical details of the social engineering campaign were not fully disclosed by the group, it was reported that the domain mckesson[.]claims was utilized. This domain pattern aligns with a broader ShinyHunters campaign previously documented by ReliaQuest's Threat Research team, which involved registering .claims domains incorporating targeted company names to impersonate help desks and IT teams.
The vishing attacks allegedly led to the compromise of several employees' Okta single sign-on accounts. ShinyHunters claims these compromised credentials were then used to access McKesson's Salesforce and Snowflake environments. The group asserts it fully compromised the Salesforce environment, including support cases, and exfiltrated a significant volume of patient-related data from Snowflake.
According to ShinyHunters, approximately 1 terabyte of data was exfiltrated over four days, between August 21 and August 25. The group clarified that the figure of 284 million refers to raw data records or lines, not necessarily unique individuals, as they have not yet fully analyzed the stolen data to determine the number of unique people affected.
ShinyHunters claims the stolen information encompasses a wide range of sensitive data, including names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment details, and physician information. The group also alleges the data includes information on deceased and terminally ill patients, prescription and medication shipment details, invoices, employee information, Salesforce records, internal communications, and data pertaining to healthcare providers and clinics utilizing McKesson's services. McKesson has not publicly confirmed the specific types of data stolen.
The extortion group stated that it contacted McKesson on August 25, after completing the data theft, demanding a ransom of $55,236,150 with a 72-hour deadline for a response. ShinyHunters claims McKesson did not respond to or negotiate the demand.
This incident follows a series of data-theft attacks attributed to ShinyHunters targeting healthcare and health technology organizations. Health-ISAC recently issued a warning to the healthcare sector about increasing ShinyHunters activity involving social engineering to compromise corporate accounts and gain access to cloud and SaaS platforms. Other healthcare technology companies reportedly targeted by ShinyHunters in recent data-theft attacks include Medtronic, DentaQuest, iRhythm, OneMedical, and AdaptHealth.






