McKesson Corporation, one of the largest pharmaceutical and healthcare distribution companies in the United States, has confirmed a data breach after the extortion group ShinyHunters claimed to have stolen close to 284 million records containing patient and internal company data.
According to BleepingComputer, McKesson discovered the intrusion on August 25, 2026. The attackers reportedly used voice phishing, commonly called vishing, to trick employees into handing over credentials for the company’s Okta single sign-on system. As part of the scheme, they registered a lookalike domain, mckesson[.]claims, to pose as internal IT or help desk staff during phone calls.
Once inside, the attackers gained access to McKesson’s Salesforce environment, including customer support cases, and its Snowflake data warehouse. Investigators believe roughly 1 terabyte of data was exfiltrated between August 21 and August 25, 2026.
ShinyHunters told reporters the stolen data includes names, home addresses, dates of birth, Social Security numbers, patient and medical record IDs, phone numbers, email addresses, Medicaid numbers, medication and allergy details, diagnoses, appointment records, physician information, and internal employee communications. Cybernews, which separately reviewed samples of the claimed data, reported that some records also appear to include sensitive categories such as terminal diagnoses. The 284 million figure represents a raw count of data rows rather than a number of unique patients, and ShinyHunters itself said it had not yet fully analyzed everything it took, meaning the true scope could still change.
The group reportedly demanded a ransom of $55,236,150 with a 72-hour deadline. McKesson does not appear to have responded to the demand or paid.
In a statement, McKesson said it “immediately activated incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts” after discovering the intrusion. The company added that it does not believe customers need to take any action at this time and described its investigation as being in its early stages. McKesson also filed a Form 8-K with the Securities and Exchange Commission, in which it said it had not yet determined whether the incident would have a material financial impact.
No software vulnerability or CVE has been tied to this incident. The breach appears to stem entirely from social engineering against employees rather than a flaw in McKesson’s systems, a pattern that has become increasingly common among groups linked to ShinyHunters this year. The same actor or affiliated groups have been connected to a string of Salesforce and Snowflake-related breaches at other large organizations throughout 2026.
Healthcare data breaches carry particular risk because the stolen information, including Social Security numbers and detailed medical histories, cannot be changed the way a password can. People whose data may have been affected should watch for phishing attempts referencing McKesson or their healthcare providers, and consider placing a fraud alert or credit freeze if McKesson later confirms their information was included.
Source: BleepingComputer, with additional reporting from Cybernews.
