Illustrative image generated with AI
McKesson discloses breach: ShinyHunters claims 284 million healthcare records stolen via vishing
ShinyHunters claims to have stolen 284 million healthcare records from McKesson via vishing, leading to a disclosed breach and $55M ransom demand.
Text generated by artificial intelligence, published without human review. AI transparency
The incident and discovery
On August 28, 2026, McKesson, one of the largest US pharmaceutical and healthcare distributors, disclosed a cybersecurity incident. The company filed a Form 8-K with the SEC and said it had detected on August 25 unauthorized access to third-party applications resulting in data exfiltration. The investigation is in its early stages. McKesson said that, as of the filing date, it has not determined that the incident is material or that it has had, or is reasonably likely to have, a material impact on its financial condition or results of operations. Official updates are available at www.mckesson.com/cybersecurity.
On the same day, August 28, the ShinyHunters criminal group claimed the attack in a statement to BleepingComputer. McKesson has not confirmed the claim nor specified which third-party applications were compromised, what access vector was used, or which data were stolen.
The claimed attack chain: vishing, Okta, Salesforce, and Snowflake
According to ShinyHunters, initial access occurred through vishing, or voice phishing, targeting multiple McKesson employees. The group claims it used the domain mckesson[.]claims to impersonate the company’s help desk or IT team. This domain matches a campaign already documented by ReliaQuest’s threat research team, which had registered .claims domains containing names or abbreviations of target companies for this purpose. The finding had appeared in a since-deleted post on X.
The vishing allegedly led to the compromise of multiple employee Okta single sign-on accounts. From there, the attackers claim to have accessed Salesforce and Snowflake environments. ShinyHunters says it fully compromised Salesforce, including support cases, and stole a much larger collection of 284 million patient data records from Snowflake. The exfiltration reportedly occurred over four days, from August 21 to August 25, 2026, totaling about 1 TB of data.
McKesson has not confirmed any details of this sequence. The exact product versions involved have not been disclosed.
Sensitive healthcare data and a $55 million ransom demand
ShinyHunters claims the stolen data includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, diseases, disabilities, appointments, and physician data. The group also lists data on deceased or terminal patients, prescriptions and drug shipments, invoices, employee data, Salesforce records, internal communications, and information on suppliers or clinics that use McKesson services.
The group notes that the 284 million is a raw count of records or rows, not unique individuals. It has not yet analyzed the data and does not know the number of unique people involved. BleepingComputer has not independently verified these claims, and McKesson has not disclosed what was actually stolen.
ShinyHunters says it contacted McKesson on August 25, 2026, after the theft, demanding a ransom of $55,236,150 with 72 hours to respond. According to the group, the company did not respond or negotiate.
McKesson's response and uncertainty about impact
McKesson has activated incident response protocols, launched an investigation, and engaged cybersecurity experts. In a note to customers, it confirmed the involvement of third-party applications and unauthorized data access and exfiltration. The company warned that customers may experience intermittent service degradation believed to be related to the attack, but clarified that it is not proactively disconnecting systems.
No specific technical mitigations for customers have been published. It is unclear which third-party applications were compromised, or whether patient data was actually exfiltrated in the claimed volume. The true scale in unique individuals remains uncertain.
An attack amid rising pressure on the healthcare sector
The attack is part of a wave of data thefts targeting healthcare and health-tech organizations attributed to ShinyHunters. Health-ISAC has recently warned healthcare organizations about the rise in social engineering attacks to compromise corporate accounts and access cloud and SaaS platforms. Other healthcare companies targeted in recent attacks include Medtronic, DentaQuest, iRhythm, OneMedical, and AdaptHealth.
For healthcare organizations, Health-ISAC recommends protecting against vishing and social engineering, monitoring .claims domains impersonating help desks or IT teams, and watching for anomalous access to Okta, Salesforce, and Snowflake. This is not a software vulnerability requiring a patch, but an identity and cloud access compromise. Companies should review authentication logs, conditional access rules, and employee reports of suspicious calls.
It is not known whether McKesson has already notified affected individual patients or employees. Those who have had dealings with McKesson should monitor for suspicious communications, bank activity, or unrecognized credit inquiries. But in the absence of public confirmation of what data was actually exfiltrated, it is too early to assess individual exposure.
Sources
This article is an original reworking based on the sources below.
