McKesson Cyberattack: ShinyHunters Claims 28 Crores Data Stolen

www.news4hackers.com-mckesson-cyberattack-shinyhunters-claims-28-crores-data-stolen-mckesson-cyberattack-shinyhunters-claims-28-crores-data-stolen

McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of sensitive patient data, with the ShinyHunters ransomware group claiming responsibility and demanding a $55.2 million ransom.

Overview of the Cybersecurity Incident

McKesson, a major healthcare and pharmaceutical distribution company, reported a cybersecurity incident on August 25, 2026, involving unauthorized intrusion into third-party applications. The breach, attributed to the ShinyHunters ransomware group, allegedly resulted in the exfiltration of 284 million patient-related records through a voice-phishing campaign targeting employee accounts. The company has not yet disclosed the specific third-party applications affected, the methods used by attackers, or the precise data categories compromised.

Details of the Breach

The incident was reported in a Form 8-K filing with the U.S. Securities and Exchange Commission. McKesson confirmed the breach involved third-party applications and unauthorized data access, activating incident response protocols and engaging cybersecurity experts. The company warned of potential service disruptions but clarified it was not proactively isolating systems within its network. Ongoing investigations aim to assess the full scope of the incident, with McKesson pledging to release further details as they become available.

Ransom Demand and Response

ShinyHunters claimed responsibility for the attack, stating it exploited voice-phishing tactics to compromise multiple McKesson employees. The group alleged the breach resulted in the unauthorized access of Okta single sign-on credentials, which were then used to infiltrate the company’s Salesforce and Snowflake environments. According to the group, approximately 1 terabyte of data was extracted between August 21 and August 25. ShinyHunters demanded a ransom of $55,236,150, granting McKesson 72 hours to respond. The company reportedly did not engage in negotiations.

According to the group, the stolen data encompasses personal identifiers such as names, addresses, birth dates, Social Security numbers, patient IDs, phone numbers, Medicaid details, medical record numbers, medication and allergy information, illness histories, disability records, appointment data, and physician information. The group also alleged the dataset includes details on deceased and terminally ill patients, prescription records, shipment logs, invoices, employee data, Salesforce records, internal communications, and information related to healthcare providers and clinics utilizing McKesson’s services.

Broader Context and Industry Trends

The incident aligns with a broader trend of data-theft attacks targeting healthcare and health technology organizations. Cybersecurity experts warn of the prevalence of social-engineering campaigns designed to infiltrate corporate accounts and access cloud-based platforms. McKesson has not yet determined whether the breach will materially impact its financial standing or operations.

Conclusion

McKesson’s cybersecurity incident highlights the growing risks of third-party vulnerabilities and social-engineering attacks in the healthcare sector. As investigations continue, the company’s transparency and response will be critical in mitigating long-term impacts on its operations and stakeholder trust.

FAQs

What data was allegedly stolen?

The ShinyHunters group claimed to have stolen 284 million patient-related records, including personal identifiers, medical information, and details on healthcare providers and clinics.

Has McKesson confirmed the breach?

McKesson confirmed the breach involved third-party applications and unauthorized data access but has not yet disclosed specific details about the affected data or systems.

What is the ransom demand?

ShinyHunters demanded a ransom of $55,236,150, but McKesson reportedly did not engage in negotiations.



About Author

en_USEnglish