Cybersecurity

McKesson Discloses Breach After ShinyHunters Claims to Have Stolen Patient Data

McKesson announced that third-party applications were accessed without authorization and data was extracted, while the ShinyHunters group claims to have stolen approximately 284 million patient-related records. Neither the company nor BleepingComputer has verified the type of data stolen or the number of individuals affected.

2026-08-28
4 min read
6 views
فريق تحرير certi.news
McKesson Discloses Breach After ShinyHunters Claims to Have Stolen Patient Data

McKesson, a U.S. company specializing in pharmaceutical distribution, healthcare services, and healthcare technology, disclosed a cybersecurity incident involving unauthorized access to and data extraction from third-party applications. The disclosure came in a filing submitted by the company to the U.S. Securities and Exchange Commission after the extortion group ShinyHunters claimed responsibility for the attack, alleging that it had obtained a large amount of patient-related data.

McKesson said it discovered the incident on August 25, 2026, and that the investigation remains in its early stages. In its disclosure, it said that as of the filing date it had not determined whether the incident was “material,” or whether it had or was reasonably likely to have a material effect on the company, its financial condition, or its results of operations.

What McKesson Confirmed

The company confirmed in a separate customer notice that the incident involved third-party applications, unauthorized access, and data extraction. It said it activated incident-response protocols immediately after discovering the event and began an investigation with the assistance of cybersecurity experts. It also warned that customers might experience intermittent service degradation, but said it was not proactively disconnecting its systems from its environment.

So far, McKesson has not disclosed the names of the affected applications, how the attackers gained entry, or the nature of the information that was extracted. It also said it would provide additional information as the scope of the incident becomes clearer.

ShinyHunters’ Claims

ShinyHunters told BleepingComputer that the attack began with voice-phishing campaigns targeting several McKesson employees, and that the attackers managed to compromise employee accounts in Okta for the single sign-on service. The group claims it used these accounts to access the Salesforce and Snowflake environments and extracted approximately one terabyte of data over four days between August 21 and 25.

The group says the Salesforce environment, including support cases, was fully compromised, and that the Snowflake data included approximately 284 million patient-related records. However, this figure does not mean that 284 million people were affected; ShinyHunters explained that it represents a raw number of records or rows, not the number of unique individuals, and acknowledged that it had not fully analyzed the data and did not know the actual number of people involved.

The list of data the group claims to have stolen includes names, addresses, dates of birth, Social Security numbers, patient identifiers, Medicaid numbers, medical-record data, medications, allergies, appointments, and physicians, as well as prescription information, drug shipments, billing, employee data, and internal communications. BleepingComputer has not independently verified these claims, and McKesson has not confirmed the contents of the data.

Why Does This Matter?

According to the information available, the incident reveals an attack path combining social engineering and single sign-on accounts with access to cloud services and business applications. The incident is particularly sensitive because McKesson handles data related to patients, healthcare providers, and pharmacies, but the scale of the impact, the type of information exposed, and the number of individuals affected remain open questions.

The source links the attack to a wave of data-theft operations attributed to ShinyHunters against healthcare and health-technology organizations, along with a previous warning from Health-ISAC about targeting corporate accounts to gain access to SaaS platforms and cloud services. It also said that the group demanded a ransom of $55,236,150 and claimed that McKesson did not negotiate with it. These details, such as the alleged use of the mckesson[.]claims domain, remain based on statements by the group or reports from other parties and do not constitute a final confirmation by the company.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news