Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming responsibility for the theft of about 284 million patient-related records. McKesson said it discovered the incident on August 25, 2026, and filed a Form 8-K with the U.S. Securities and Exchange Commission acknowledging the breach on August 28.
SaaS pivot: Salesforce and Snowflake environments hit
According to ShinyHunters, operators launched a voice phishing (vishing) campaign against multiple McKesson employees using the impersonation domain mckesson[.]claims, a pattern documented by ReliaQuest as part of a wider .claims help-desk lure campaign. The vishing compromised employees' Okta single sign-on accounts, which the group then used to reach McKesson's Salesforce and Snowflake environments and exfiltrate roughly 1 TB of data between August 21 and August 25.
284 million records is a line count, not a patient count
ShinyHunters told BleepingComputer the widely reported 284 million figure is a raw record count from Snowflake tables — patient IDs, prescriptions, invoices and internal messages — not a count of unique individuals. The group has not yet completed its own analysis of the dataset. The stolen records reportedly include names, addresses, dates of birth, Social Security numbers, Medicaid numbers, medical record numbers, medications, allergies, illnesses, appointment information, and physician information, alongside employee data and Salesforce support cases.
$55 million ransom demand refused
ShinyHunters said it contacted McKesson on August 25 with a $55,236,150 ransom demand and a 72-hour deadline, and that the company has not entered negotiations. McKesson has confirmed unauthorized access to and exfiltration from third-party applications but has not publicly identified which systems were compromised or what specific data was taken. Customers may see intermittent service degradation, but McKesson said it is not proactively taking its own systems offline.
Part of a broader healthcare targeting wave
Health-ISAC has warned that ShinyHunters is running an accelerating campaign against healthcare and health-technology firms; recent victims include Baxter International, Medtronic, DentaQuest, iRhythm, OneMedical and AdaptHealth. Investigators point to a common pattern: SaaS help-desk impersonation, Okta compromise, and rapid staged exfiltration from customer clouds. The healthcare and government cyber threat surface continues to widen as extortion groups pivot to identity-first attacks.
Reporting based on coverage from BleepingComputer, CyberInsider, McKesson's SEC 8-K filing and Health-ISAC.
