ShinyHunters Claims 284 Million Patient Records Breached from McKesson

www.news4hackers.com-shinyhunters-claims-284-million-patient-records-breached-from-mckesson-shinyhunters-claims-284-million-patient-records-breached-from-mckesson

ShinyHunters asserts it obtained 284 million patient records from McKesson, a healthcare corporation that disclosed a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration.

McKesson’s Cybersecurity Incident

McKesson, a leading U.S. healthcare entity supplying pharmaceuticals, medical equipment, and healthcare products to pharmacies, hospitals, and clinics, reported the breach. The intrusion was identified on August 25, 2026, according to an SEC filing. The organization stated the investigation remains in its initial phase and has not yet determined if the incident will significantly impact its financial standing or operational continuity. McKesson’s cybersecurity page provides a public-facing explanation of the breach, aligning with standard corporate communications.

McKesson’s Statement

“Our assessment, supported by cybersecurity experts, confirms unauthorized access to specific third-party applications and data removal linked to a subset of customers within our Oncology Multispecialty and Medical-Surgical business units,” stated Francisco Fraga, EVP of Chief Information and Technology Officer at McKesson. The company noted its internal security team and external specialists are addressing the incident’s impact on system functionality and operations, with potential service disruptions for customers attributed to the breach. “At this time, we do not believe customers need to take action, and we are not actively isolating systems within our environment,” Fraga said. “We maintain close monitoring of our environment and implement measures to ensure operational security and reliability,” he added.

ShinyHunters’ Claims and Methods

While McKesson did not disclose the perpetrators or exact data volume, evidence points to ShinyHunters as the responsible party. The group informed BleepingComputer that it infiltrated McKesson via vishing calls targeting employees, then leveraged stolen credentials to compromise Okta single sign-on accounts. From there, the group claims access to McKesson’s Salesforce and Snowflake systems, extracting approximately one terabyte of data over four days.

Ransom Demand and Data Exposure

ShinyHunters reported contacting McKesson on August 25 following the theft, demanding $55,236,150 with a 72-hour response window. The group stated McKesson did not respond. The claimed 284 million records represent database entries rather than unique individuals. The data includes names, addresses, birth dates, Social Security numbers, patient identifiers, Medicaid information, medical record numbers, medication and allergy details, physician data, internal Salesforce records, and employee information. Independent verification of these claims remains pending.

Industry-Wide Cybersecurity Concerns

The healthcare sector continues to face heightened cyber threats. Recent reports highlight similar incidents, such as the Boston Scientific breach, underscoring the prevalence of cyberattacks against medical technology firms this year.



About Author

en_USEnglish