Security

McKesson Discloses Breach as ShinyHunters Claims 284 Million Patient Records

Pharmaceutical distributor McKesson disclosed a cybersecurity incident on August 28 after the ShinyHunters extortion group claimed it stole roughly 284 million patient-related records via vishing attacks on employees.

L
By Loren Grush Security Editor
August 31, 2026 / 5 min read

McKesson, the healthcare and pharmaceutical distribution giant that moves roughly a third of the prescription drugs sold in the United States, disclosed a cybersecurity incident on August 28 in a Form 8-K filing with the SEC. The company said it discovered the incident on August 25 and that it involved unauthorized access to third-party applications and the exfiltration of data. CyberInsider first reported the breach earlier in the day.

ShinyHunters Claims 284 Million Records

The ShinyHunters extortion group told BleepingComputer it was behind the attack, claiming it gained access through voice phishing, or vishing, social engineering campaigns against multiple McKesson employees. The attackers allegedly compromised Okta single sign-on accounts and used them to reach McKesson's Salesforce and Snowflake environments, exfiltrating about 1 terabyte of data over four days between August 21 and August 25.

ShinyHunters says the stolen data includes approximately 284 million patient-related records, a figure that counts rows rather than unique patients. The claimed data spans names, addresses, dates of birth, Social Security numbers, patient IDs, Medicaid numbers, medication and allergy information, and physician details. McKesson has not confirmed the attacker's claims and says its investigation remains in early stages.

Ransom Demand and Response

The group says it contacted McKesson after completing the data theft and demanded a ransom of $55,236,150 with a 72-hour deadline. According to ShinyHunters, McKesson did not respond to or negotiate over the demand. McKesson has not confirmed which third-party applications were compromised or how attackers gained access.

A Wave of Healthcare Extortion

The incident adds to an ongoing wave of data-theft attacks on healthcare and health technology organizations attributed to ShinyHunters, which have relied on vishing against employees to reach cloud identity layers. Regulators are watching closely; under HIPAA breach rules, a confirmed incident of this scale would trigger public reporting to the Department of Health and Human Services and likely draw state attorneys general scrutiny.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.