McKesson discloses breach after ShinyHunters claims patient data theft

McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft on Massive Scale

Healthcare giant McKesson has announced a major cybersecurity incident after the ShinyHunters extortion group claimed to have stolen 284 million patient data records. The breach, which occurred between August 21 and 25, involved unauthorized access to third-party applications and data exfiltration from McKesson’s Salesforce and Snowflake environments.

McKesson, one of the largest healthcare companies in the US, provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies. The company discovered the incident on August 25 and is currently investigating its scope and impact. In a filing with the Securities and Exchange Commission (SEC), McKesson stated that it had not determined whether the breach was material or would have a significant effect on the company’s financial condition.

According to ShinyHunters, the attackers gained access to McKesson’s systems through voice phishing social engineering attacks against multiple employees. The group used vishing tactics to compromise Okta single sign-on accounts, which were then used to access sensitive areas of the company’s infrastructure. ShinyHunters claims that it stole approximately 1TB of data over four days, including patient-related information from Snowflake.

It is essential to note that the reported figure of 284 million patient records does not necessarily mean that this many patients are affected. The actual number might be lower due to duplicate or aggregated records. ShinyHunters clarified that the figure represents a raw count of data records rather than unique individuals.

The breach highlights the importance of robust cybersecurity measures and employee education in preventing social engineering attacks. It also underscores the need for organizations to prioritize incident response planning, including regular security audits and penetration testing. McKesson’s notice to customers warns that they may experience intermittent service degradation related to the attack, although the company has not proactively disconnected systems within its environment.

As this incident unfolds, it serves as a reminder of the ongoing threat posed by sophisticated attackers like ShinyHunters. With their tactics evolving to exploit vulnerabilities in human psychology and technology, organizations must remain vigilant and proactive in protecting themselves against these threats. By doing so, they can minimize the risk of data breaches and safeguard sensitive information from falling into the wrong hands.

For McKesson customers and partners, this breach serves as a wake-up call to review their own cybersecurity posture and ensure that robust measures are in place to prevent similar incidents. The incident also emphasizes the importance of having a solid incident response plan in place, which includes timely communication with stakeholders and affected parties. By prioritizing security awareness and taking proactive steps to mitigate risks, organizations can better protect themselves against the ever-evolving threat landscape.


Source: Bleeping Computer — 2026-08-28