McKesson has disclosed a cybersecurity incident involving unauthorised access to third-party applications and the theft of data, while the ShinyHunters extortion group has claimed responsibility and said it exfiltrated about 284 million patient-related data records.
The U.S. healthcare and pharmaceutical distribution company said it discovered the incident on August 25, 2026. Its investigation remains at an early stage, and McKesson has not publicly disclosed which third-party applications were compromised, how attackers gained access, or exactly what information was taken.
The company disclosed the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission and said it had not determined that the incident was material or reasonably likely to have a material impact on its financial condition or results of operations.
Third-Party Applications and Data Exfiltration Confirmed
McKesson confirmed that the incident involved third-party applications and the unauthorised access and exfiltration of data. The company said it activated incident response protocols after discovering the breach, launched an investigation and engaged cybersecurity specialists to assist with the response.
Customers were warned that they could experience intermittent service degradation believed to be connected to the attack. McKesson said it was not proactively disconnecting systems within its environment.
The investigation is continuing to determine the full scope of the incident, and the company said it would provide additional information as its understanding develops.
Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions
ShinyHunters Claims Voice-Phishing Attack
ShinyHunters claimed it gained access after conducting voice-phishing, or vishing, attacks against multiple McKesson employees. The group said the attacks led to the compromise of several employees’ Okta single sign-on accounts, which were then allegedly used to access the company’s Salesforce and Snowflake environments. According to the group, approximately 1TB of data was exfiltrated over four days between August 21 and August 25.
ShinyHunters said the stolen Snowflake data contained about 284 million patient-related data records. It clarified that this figure represents a raw count of records rather than 284 million unique patients, and said it had not yet determined how many individuals were represented in the dataset.
Group Claims Sensitive Patient and Corporate Data Was Taken
ShinyHunters claims the stolen information includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information and physician details.
The group also claimed the data includes information relating to deceased and terminally ill patients, prescriptions, medication shipments, invoices, employee information, Salesforce records, internal communications and healthcare providers and clinics using McKesson services.
Those claims have not been independently verified, and McKesson has not publicly confirmed what information was stolen.
ShinyHunters further claimed it demanded a ransom of $55,236,150 after completing the data theft on August 25 and gave McKesson 72 hours to respond. The group said the company did not negotiate over the demand.
The incident comes amid a broader wave of data-theft attacks targeting healthcare and health technology organisations, with warnings issued about social-engineering campaigns aimed at compromising corporate accounts and gaining access to cloud and SaaS platforms.