McKesson discloses breach after ShinyHunters claims patient data theft

McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft

Healthcare giant McKesson has revealed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the notorious extortion group ShinyHunters claiming responsibility for stealing 284 million patient data records. This massive breach is a stark reminder of the vulnerabilities in healthcare organizations’ systems and the threat posed by sophisticated attackers.

McKesson is one of the largest pharmaceutical distributors in the United States, providing medicines, medical supplies, technology, and services to healthcare providers and pharmacies. The company’s investigation into the breach remains in its early stages, but it has confirmed that the incident involved third-party applications and the unauthorized access and exfiltration of data.

According to ShinyHunters, the attackers gained access by conducting voice phishing (vishing) social engineering attacks against multiple McKesson employees. By impersonating IT teams or help desks, the attackers were able to trick employees into divulging sensitive information, including Okta single sign-on credentials. These compromised accounts allowed the attackers to access the company’s Salesforce and Snowflake environments.

The stolen data includes approximately 284 million raw data records from Snowflake, which contains patient-related information. ShinyHunters claims that it exfiltrated about 1TB of data over four days between August 21 and August 25. While this figure is staggering, it’s essential to note that the breach may not have impacted 284 million unique patients.

McKesson has taken steps to address the incident by activating its incident response protocols, launching an investigation, and engaging leading cybersecurity experts to assist in the response. The company has warned customers that they may experience intermittent service degradation related to the attack but has not proactively disconnected systems within its environment.

The use of vishing attacks as a means of gaining access is particularly concerning, as it highlights the threat posed by sophisticated attackers who can manipulate individuals into divulging sensitive information. ShinyHunters’ tactics are also noteworthy, as they used domains matching the company[.]claims pattern to impersonate help desks and IT teams.

As this incident unfolds, it serves as a stark reminder of the importance of robust cybersecurity measures in healthcare organizations. While McKesson has taken steps to address the breach, it’s crucial for all parties involved to remain vigilant and proactive in protecting sensitive information.

In the face of such massive breaches, it’s essential for individuals and organizations to take practical steps to mitigate risks. This includes staying informed about potential threats, implementing robust security measures, and being cautious when receiving unsolicited calls or emails from unknown sources. By working together, we can reduce the likelihood of similar incidents occurring in the future.


Source: Bleeping Computer — 2026-08-28