McKesson Data Breach: ShinyHunters Claims 284 Million Records Stolen, Demands $55 Million Ransom
核心洞察
McKesson disclosed unauthorized access and data exfiltration from third-party applications in an SEC filing on August 28, 2026, after detecting the intrusion on August 25, 2026.
The extortion group ShinyHunters (搜索) claims it stole roughly 284 million data records from McKesson's Snowflake and Salesforce environments, a figure representing database rows rather than confirmed unique patients.
Hackers say they used vishing calls to hijack Okta single sign-on accounts, then moved laterally into cloud systems over a four-day window between August 21 and August 25.
McKesson Corporation, one of the largest pharmaceutical distributors and healthcare companies in the United States, has become the latest target in a widening wave of cyberattacks against American healthcare organizations. The company disclosed unauthorized access and data exfiltration from third-party applications in a filing with the Securities and Exchange Commission on August 28, 2026, after first flagging the incident internally on August 25, 2026. The extortion group ShinyHunters (搜索) has claimed responsibility, asserting it stole roughly 284 million data records and demanding a ransom of $55,236,150.
The Breach and ShinyHunters' Claims
McKesson's own disclosure was carefully worded and short on detail, but it confirmed the core of the story: intruders gained access to third-party applications and pulled out data before the company detected the activity. The company told the SEC that its investigation remained "in its early stages" and that it had not yet determined whether the incident was financially material.
McKesson's chief information and technology officer, Francisco Fraga, told customers that the confirmed unauthorized access and data exfiltration affected "a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units." He added that the company was not proactively disconnecting systems and did not believe customers needed to take action, while acknowledging the investigation was ongoing.
ShinyHunters (搜索), described as one of the most active extortion groups targeting healthcare, told Bleeping Computer it exfiltrated roughly one terabyte of data over four days, between August 21 and August 25, and that the Snowflake environment alone yielded about 284 million data records. The group subsequently clarified that this number reflects raw database rows rather than a confirmed count of unique patients, and admitted it has not fully analyzed the haul to determine how many individuals are actually represented. ShinyHunters further told CyberInsider that the 284 million records are linked to tens of millions of patients, though the exact number of people affected remains unknown.
How the Hackers Broke In
According to ShinyHunters (搜索), the attack began with voice-phishing, or vishing, calls targeting two McKesson employees. The group used a lookalike domain, mckesson[.]claims, built to impersonate the company's internal help desk or IT team — a tactic matching a broader pattern that researchers at ReliaQuest had already been tracking across multiple organizations using the ".claims" naming scheme.
Once the attackers tricked employees into handing over credentials, they took over Okta single sign-on accounts. From there, ShinyHunters (搜索) says it pivoted into McKesson's Salesforce and Snowflake cloud environments, where the bulk of the company's patient and business data resides.
What Was Allegedly Stolen
The categories of data allegedly stolen are extensive. ShinyHunters (搜索) says the trove includes names, home addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment details, and physician information.
The group also claims the stolen files touch deceased and terminally ill patients, prescription and medication shipment records, invoices, internal communications, and information tied to healthcare providers and clinics that use McKesson's services. CyberInsider reported that the allegedly stolen data includes hospice and terminal illness information, causes of death, autopsy details, sexual orientation, and predictive health data such as disease-risk assessments including cancer predictions linked to individual patients.
Separately from patient records, the hackers say McKesson employee information — including home addresses — was also swept up in the exfiltration, extending the fallout beyond the company's customer base. TechCrunch reported it verified a small sample of the leaked data against public records, though none of the broader claims have been independently confirmed by outside researchers or McKesson itself.
A $55 Million Ultimatum and McKesson's Response
Extortion, not just theft, appears to be the endgame. ShinyHunters (搜索) told Bleeping Computer it contacted McKesson immediately after finishing the data theft on August 25 and demanded a ransom of exactly $55,236,150, giving the company a 72-hour deadline to respond. According to the group, McKesson never engaged with the demand at all.
Publicly, McKesson has stuck to a narrow script. Spokesperson Kristina Chang told TechCrunch the company "continues to operate in all lines of business" and said McKesson does not believe there is ongoing unauthorized activity inside its systems. The company confirmed customers could experience intermittent service degradation tied to the incident, but declined to answer specific questions about the ransom demand or the number of individuals whose data was affected.
In a statement to CyberInsider, a McKesson spokesperson said the company is "in the early stages of investigating a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data," adding that it "immediately activated our incident response protocols, launched an investigation and engaged leading cybersecurity experts."
A Widening Pattern of Healthcare Cyberattacks
McKesson is not an isolated case — it is the latest entry in a fast-moving wave of attacks against U.S. healthcare and medtech companies. A cyberattack struck medical device manufacturer Boston Scientific last week, causing significant disruption to much of its network, echoing an earlier incident at fellow device maker Stryker, where hackers abused internal tools to remotely wipe thousands of employee devices.
Abbott Laboratories and Medtronic have both experienced cyberattacks in recent months. Data breaches impacted health tech firm TriZetto (搜索) and electronic patient records provider CareCloud (搜索), each affecting more than 3 million patients. ShinyHunters (搜索) itself has also claimed credit for breaches at Amazon-owned One Medical (搜索) and dental insurer DentaQuest (搜索), along with attacks on Medtronic, iRhythm (搜索), and AdaptHealth (搜索).
Health-ISAC has already warned healthcare organizations about the rising tide of ShinyHunters (搜索) attacks built around social engineering aimed at corporate accounts and cloud or SaaS platforms — exactly the playbook allegedly used against McKesson. For an industry that stores some of the most sensitive personal data that exists, the repetition of this same vishing-to-cloud-breach pattern suggests attackers have found a method that consistently works, and healthcare cyberattacks tied to groups like ShinyHunters show no sign of slowing down.
