McKesson, a major U.S. healthcare and pharmaceutical distribution company, has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. The extortion group ShinyHunters has claimed responsibility, stating it stole roughly 284 million patient data records. The breach affects McKesson’s partners, customers, and their patients, as the company provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies nationwide.
McKesson discovered the incident on August 25, 2026, and disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission. The company stated that its investigation remains in the early stages, and it has not yet determined whether the incident is material to its financial condition or results of operations. In a notice to customers, McKesson confirmed that the incident involved third-party applications and the unauthorized access and exfiltration of data. The company said it activated incident response protocols, launched an investigation, and engaged cybersecurity experts to assist.
The company warned that customers may experience intermittent service degradation believed to be related to the attack. However, McKesson said it was not proactively disconnecting systems within its environment. At this time, McKesson has not publicly identified which third-party applications were compromised, how the attackers gained access, or what specific information was stolen beyond the general claims from ShinyHunters.
ShinyHunters told BleepingComputer that it gained access through voice phishing, or vishing, social engineering attacks against multiple McKesson employees. The group said these attacks led to the compromise of several employees’ Okta single sign-on accounts, which were then used to access McKesson’s Salesforce and Snowflake environments. ShinyHunters claimed it fully compromised the Salesforce environment, including support cases, and exfiltrated about 1TB of data over four days between August 21 and August 25.
According to ShinyHunters, the stolen Snowflake data contains approximately 284 million data records of patient-related information. The group clarified that this figure is a raw count of records or lines, not a count of unique individuals, and that it has not fully analyzed the data to determine how many distinct people are represented. The claimed stolen data includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information, and physician information.
The group also claims the data contains information related to deceased and terminally ill patients, prescriptions and medication shipments, invoices, employee information, Salesforce records, internal communications, and healthcare providers and clinics using McKesson’s services. BleepingComputer learned from another source that the threat actors used the domain mckesson[.]claims as part of the attack. This matches a ShinyHunters campaign tracked by ReliaQuest’s Threat Research team, which documented the group registering company[.]claims domains to impersonate help desks and IT teams of targeted organizations.
More cybersecurity news from TechManNews.








