en
Back to the list

McKesson data breach: hackers claim 284 million records stolen, demand $55M

source-logo  en.cryptonomist.ch 1 h
image

A pharmaceutical distribution giant just became the newest name on a growing list of American healthcare companies hit by hackers hunting for patient records. The McKesson data breach, disclosed on August 28, 2026, has already triggered a ransom demand worth tens of millions of dollars and put sensitive medical information for what could be millions of patients at risk.

Key takeaways

  • McKesson detected unauthorized access to third-party applications on August 25, 2026, and disclosed the incident in an SEC filing.
  • The extortion group ShinyHunters claims it stole roughly 284 million data records from McKesson’s Snowflake and Salesforce environments — a figure representing database rows, not confirmed unique patients.
  • Hackers say they used vishing calls to trick employees and hijack Okta single sign-on accounts, then moved laterally into cloud systems over a four-day window between August 21 and August 25.
  • ShinyHunters demanded a ransom of $55,236,150 and gave McKesson 72 hours to respond; the company reportedly never did.
  • McKesson confirmed intermittent service degradation but declined to say how many people were affected or what ransom demand it received.

The Breach and ShinyHunters’ Claims

McKesson’s own disclosure was carefully worded and short on detail, but it confirmed the core of the story: intruders got into third-party applications and pulled out data before the company caught on. The McKesson data breach was first flagged internally on August 25, 2026, and the company told the Securities and Exchange Commission its investigation was still “in its early stages,” adding it had not yet determined whether the incident was financially material.

McKesson’s chief information and technology officer, Francisco Fraga, told customers that the confirmed unauthorized access and data exfiltration affected “a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units.” He also said the company was not proactively disconnecting systems and did not believe customers needed to take action, though he acknowledged the investigation was ongoing.

How the Hackers Broke In

ShinyHunters, described as one of the most active target="_self">lookalike domain, mckesson[.]claims, built to impersonate the company’s internal help desk or IT team, a tactic that matches a broader pattern researchers at ReliaQuest had already been tracking across multiple targeted organizations using the “.claims” naming scheme.

Once the attackers tricked employees into handing over credentials, they took over Okta single sign-on accounts. From there, ShinyHunters says it pivoted into McKesson’s Salesforce and Snowflake cloud environments, where the bulk of the company’s patient and business data lives.

What They Say They Stole

The scale of the claimed theft is what makes this incident stand out. ShinyHunters told Bleeping Computer it exfiltrated roughly one terabyte of data over four days, between August 21 and August 25, and that the Snowflake environment alone yielded about 284 million data records. The group has since clarified that this number reflects raw database rows rather than a confirmed count of unique patients, and it admitted it has not fully analyzed the haul to determine how many individuals are actually represented in it.

That distinction matters. It means the true scope of the McKesson data breach remains genuinely uncertain, even according to the hackers themselves, and McKesson has not offered its own estimate.

Regardless of the exact headcount, the categories of data allegedly stolen are extensive. ShinyHunters says the trove includes names, home addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment details, and physician information. The group also claims the stolen files touch deceased and terminally ill patients, prescription and medication shipment records, invoices, internal communications, and information tied to healthcare providers and clinics that use McKesson’s services. TechCrunch reported it verified a small sample of the leaked data against public records, though none of the broader claims have been independently confirmed by outside researchers or McKesson itself.

Separately from patient records, the hackers say McKesson employee information — including home addresses — was also swept up in the exfiltration, extending the fallout beyond the company’s customer base.

A $55 Million Ultimatum and McKesson’s Response

Extortion, not just theft, appears to be the endgame here. ShinyHunters told Bleeping Computer it contacted McKesson right after finishing the data theft on August 25 and demanded a ransom of exactly $55,236,150, giving the company a 72-hour deadline to respond. According to the group, McKesson never engaged with the demand at all.

Publicly, McKesson has stuck to a narrow script. Spokesperson Kristina Chang told TechCrunch the company “continues to operate in all lines of business” and said McKesson does not believe there is ongoing unauthorized activity inside its systems. The company confirmed customers could experience intermittent service degradation tied to the incident, but it declined to answer specific questions about the ransom demand or the number of individuals whose data was affected.

That silence is notable on its own. Why this matters: when a company handling patient data at McKesson’s scale won’t confirm how many people are affected, patients, providers, and regulators are left guessing at the real exposure — and that uncertainty tends to linger long after the initial headlines fade.

A Widening Pattern of Healthcare Cyberattacks

McKesson is not an isolated case — it’s the latest entry in a fast-moving wave of attacks against U.S. healthcare and medtech companies. Just A cyberattack struck medical device manufacturer Boston Scientific last week, causing significant disruption to much of its its network offline, echoing an earlier incident at fellow device maker Stryker, where hackers abused internal tools to remotely wipe thousands of employee devices.

Abbott Laboratories and Medtronic have both experienced cyberattacks in recent months as well. Data breaches impacted health tech firm TriZetto and electronic patient records provider CareCloud, each affecting more than 3 million patients. ShinyHunters itself has also claimed credit for breaches at Amazon-owned One Medical and dental insurer DentaQuest, along with attacks on Medtronic, iRhythm, and AdaptHealth.

Health-ISAC has already warned healthcare organizations about the rising tide of ShinyHunters attacks built around social engineering aimed at corporate accounts and cloud or SaaS platforms — exactly the playbook allegedly used against McKesson. For an industry that stores some of the most sensitive personal data that exists, the repetition of this same vishing-to-cloud-breach pattern suggests attackers have found a method that consistently works, and healthcare cyberattacks tied to groups like ShinyHunters show no sign of slowing down.

FAQ

Who was responsible for the McKesson data breach?

The hacking group ShinyHunters claimed responsibility for the cyberattack, saying it gained access through vishing calls and social engineering aimed at McKesson employees.

What kind of data was stolen in the cyberattack on McKesson?

ShinyHunters claims it took roughly 284 million data records containing personal and protected health information, along with employee personal data such as home addresses. The figure reflects database rows rather than a confirmed number of unique patients.

How did the hackers access McKesson’s systems?

According to the hackers, vishing calls tricked employees into giving up credentials, which were used to hijack Okta single sign-on accounts. From there, the attackers moved into McKesson’s cloud-hosted Salesforce and Snowflake environments to extract data.

Did McKesson pay the ransom demanded by the hackers?

McKesson declined to disclose details about any ransom payment. ShinyHunters says it demanded $55,236,150 with a 72-hour deadline and that McKesson never responded to the demand.

Article produced with the assistance of artificial intelligence and reviewed by the editorial team.

en.cryptonomist.ch