Healthcare giant McKesson confirms data breach following ShinyHunters claims of 284m stolen records
- Marijan Hassan - Tech Journalist
- 15 hours ago
- 2 min read
Healthcare and pharmaceutical distribution giant McKesson Corporation has confirmed a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration. The disclosure follows claims by the criminal extortion syndicate ShinyHunters that it compromised internal systems and extracted 284 million data records containing sensitive patient and medical information.

In a Form 8-K filing submitted to the U.S. Securities and Exchange Commission (SEC) and an accompanying customer advisory, McKesson confirmed discovering the intrusion on August 25, 2026. The company stated that forensic investigations are in early stages and that the breach has not impacted its operations and finances.
Vishing Vector and Third-Party Cloud Intrusion
According to communications from ShinyHunters, the extortion group gained initial entry by executing voice phishing (vishing) social engineering attacks against multiple McKesson employees.
The group claims it compromised employee Okta single sign-on (SSO) credentials, allowing them to access and exfiltrate data from McKesson's corporate Salesforce and Snowflake data warehouse environments between August 21 and August 25:
Salesforce Environment: The threat group claims full access to internal customer support logs, employee communications, and provider records.
Snowflake Data Warehouse: The threat actors allegedly exfiltrated roughly 1 terabyte of data containing approximately 284 million individual data records.
ShinyHunters specified that the 284 million figure represents a raw line-item count of database entries rather than 284 million unique individuals.
Demanded Ransom and Alleged Data Exposure
ShinyHunters issued a $55.2 million ransom demand to McKesson, giving the company a 72-hour deadline to negotiate before public leak procedures begin. The group claims McKesson ignored the initial payment window.
Operational Impact and Industry Response
McKesson confirmed that external incident response specialists are auditing affected environments and supporting mitigation efforts. While core pharmaceutical distribution networks remain functional, McKesson cautioned customers that some third-party applications could experience intermittent service interruptions as forensic work continues.
The incident highlights a persistent trend of vishing campaigns targeting corporate identity providers and cloud repositories across the healthcare sector, following similar social engineering intrusions across major enterprise networks throughout 2026.












