Articles

McKesson Breach: ShinyHunters Claims 284M Records

McKesson disclosed a breach tied to third-party apps after ShinyHunters claimed it stole 284 million patient records via Salesforce and Snowflake. What's known so far.

Chisato Chisato · · 5 min read
A figure at a keyboard in a dark room lit by monitors, representing a threat-actor data-theft extortion attack

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of data, after the extortion group ShinyHunters claimed it had stolen a trove of patient records from the company. McKesson said it discovered the incident on August 25, 2026, and that its investigation remains in the early stages.

The scale being claimed is enormous. ShinyHunters says it exfiltrated data amounting to 284 million patient records — a figure that, taken at face value, would rank among the largest healthcare-related data thefts ever reported. But the number comes with an important caveat that reshapes how it should be read.

What McKesson has confirmed — and what it hasn’t

McKesson’s public statement is deliberately narrow. A spokesperson confirmed that the company identified a cybersecurity incident, that it involves unauthorized access to and exfiltration of data from third-party applications, and that an investigation into the scope is underway. The company has not confirmed the number of affected individuals, the specific data elements involved, or the identity of the attacker. That gap between what the victim will confirm and what the threat actor is claiming is typical of the earliest days of a breach disclosure, and it is where most of the current uncertainty lives.

Crucially, ShinyHunters itself has walked back the headline number. The group clarified that 284 million is a raw count of records, or lines of data — not a count of unique individuals. It also said it has not yet fully analyzed the stolen data and does not know how many distinct people are represented. A single patient can appear across many records — prescriptions, appointments, provider interactions — so the number of real people affected is almost certainly far lower than 284 million, though it could still be very large. Until McKesson completes its own forensic review, the true count remains unknown.

How the attack reportedly happened

According to the threat actor, the intrusion did not rely on a novel exploit or a zero-day vulnerability. Instead, ShinyHunters says it voice-phished two McKesson employees — a social-engineering technique, sometimes called vishing, in which attackers call staff and manipulate them into granting access or approving fraudulent requests. With that foothold, the group says it then extracted data from McKesson’s Salesforce and Snowflake instances.

That pattern is the signature of a campaign that has torn through corporate America over the past several months. ShinyHunters has industrialized the tactic of tricking employees into authorizing access to cloud platforms — particularly Salesforce environments — and then bulk-downloading whatever customer and operational data those platforms hold. The technique sidesteps the hardened perimeter defenses that enterprises have spent years building, because it targets the one component that no firewall protects: a human being who believes they are helping a colleague or a vendor.

The data ShinyHunters claims to have taken is the sensitive core of a healthcare distributor’s records: full names, home addresses, dates of birth, phone numbers, email addresses, and Social Security numbers, alongside healthcare-specific fields such as patient IDs, Medicaid numbers, medical record numbers, medication and allergy information, details of illnesses and disabilities, appointment information, and physician data. If that inventory is accurate, it combines everything needed for identity theft with intimate medical detail that cannot be reissued the way a credit card can.

The extortion demand

ShinyHunters says it demanded a ransom of $55,236,150 and gave McKesson 72 hours to respond. According to the group, McKesson did not respond to or negotiate over the demand. That refusal, if accurate, is consistent with guidance from law enforcement and many incident-response firms, which discourage paying extortion demands on the grounds that payment funds further attacks and offers no guarantee the stolen data is actually deleted.

The consequences of a large breach rarely end with the extortion window, however. By August 29, law firms had already begun publicizing investigations into potential claims on behalf of affected individuals — the opening move in the class-action litigation that now follows nearly every major healthcare breach in the United States, independent of whether any ransom is ever paid.

Part of a much larger campaign

McKesson is not an isolated victim. It is the latest name in a sprawling ShinyHunters campaign that security researchers have linked to breaches at hundreds of companies, many of them reached through Salesforce Experience Cloud and connected SaaS platforms. Within healthcare alone, the group’s recent targets are reported to include Medtronic, DentaQuest, iRhythm, One Medical, and AdaptHealth, and the broader wave has swept in consumer names well outside the sector.

The pattern echoes earlier incidents this year that followed the same third-party, social-engineering playbook, from the ShinyHunters breach at Carhartt to the data theft at the Moody Bible Institute and the Oracle PeopleSoft campaign. It also rhymes with a wider run of cloud-related exposures, including the Amgen cloud data breach, that have made third-party and SaaS platforms the preferred hunting ground for data-theft extortion crews.

What it means

The McKesson breach is a case study in where enterprise risk has migrated. The attackers did not break Nvidia-grade cryptography or chain together exotic exploits; they called two employees and talked their way into a cloud platform. That is both the most alarming part of the story and the most instructive. As companies concentrate their most sensitive data inside a handful of SaaS platforms, the security of that data increasingly depends on the judgment of individual staff members under pressure on a phone call — and on the access controls, monitoring, and download limits configured around those platforms.

The disputed record count is a second, quieter lesson. Threat actors have a strong incentive to publicize the largest possible number, because a bigger figure means more leverage in extortion and more attention for their brand among criminal peers. Responsible readers — and responsible reporting — should treat the 284 million claim as an upper bound on data volume, not a count of victims, until McKesson’s forensic review produces a verified figure. That review will take weeks, and the real measure of this breach will not be the ransom demand or the raw line count, but how many patients ultimately receive notification letters and how much of their most permanent personal data is already circulating. For anyone whose records pass through the U.S. healthcare distribution system, the practical response is the familiar one: watch for identity-theft and medical-fraud activity, and assume that sensitive data, once taken, does not come back.

Chisato Chisato · · 5 min read

Carhartt Data Breach: ShinyHunters Claims 50GB Theft

ShinyHunters says it stole 50GB from Carhartt, including millions of customer records, after a rejected $3.3M ransom. What's in the leak and what it means.

#Security #Data Breach #ShinyHunters
Chisato Chisato · · 6 min read

France Tax Agency Breach: 678,000 Records Stolen

France's tax authority DGFiP confirmed a breach exposing data on roughly 678,000 taxpayers, disclosed only after a hacker's claim surfaced on a crime forum.

#Security #Data Breach #Privacy