Contained High impact Data breach Checked 1d ago

ShinyHunters claims 284 million McKesson patient records

McKesson, one of the largest US healthcare and pharmaceutical distributors, confirmed a cybersecurity incident involving unauthorized access to third party cloud applications and theft of data tied to a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. The extortion group ShinyHunters claims it stole records covering tens of millions to as many as 284 million patients and has demanded a ransom reported at about 55 million dollars. McKesson says it continues to operate across all business lines and believes there is no ongoing unauthorized activity, though customers may still see occasional service issues tied to the incident.

Started
Aug 28, 2026
Latest activity
Sep 2, 2026
Attributed to
ShinyHuntersSuspected
Where
United States
Sectors
Healthcare
Scale
one healthcare distributor

Current status

A September 3 report repeated McKesson's statement that the theft affected a subset of customers and that no ongoing unauthorized activity was believed to remain; no broader scope or closure was reported.

Contained: The attack has been stopped or blocked. Recovery and investigation are still running.

Who is behind it

McKesson has not named an attacker; ShinyHunters' account of vishing and Okta/Salesforce/Snowflake access, reported by BleepingComputer and TechCrunch, remains the group's own claim, not a McKesson or government confirmation.

Impact

Attackers gained unauthorized access to third-party cloud applications (reported by the attacker group as Okta, Salesforce, and Snowflake) used by McKesson and removed data. ShinyHunters claims records for tens of millions of patients, including sensitive details such as Social Security numbers, diagnoses, medications, and autopsy information, were stolen. McKesson has now confirmed theft occurred and narrowed the confirmed scope to a subset of customers in two business units, but has not confirmed the total number of people affected or the 284 million figure, and says it does not believe further customer action is required at this time.

What to do

Watch for an official notification from McKesson before taking any action.

Timeline

  1. Sep 3, 2026

    Cyber Defense Magazine reported McKesson's existing confirmation that data was stolen from a subset of customers and that the company believed there was no ongoing unauthorized activity. It reported no new victim count, leak, attribution, or closure.

    Containedcyberdefensemagazine.com
  2. Sep 2, 2026

    McKesson confirmed on its cybersecurity information center that unauthorized access and data exfiltration were tied to a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units; a company spokesperson said McKesson continues to operate across all business lines and believes there is no ongoing unauthorized activity in its systems, though it did not disclose how many people were affected.

    Containeddigitalmarketreports.com
  3. Sep 1, 2026

    ShinyHunters told reporters the stolen McKesson data covers tens of millions of patients and includes sensitive records such as autopsy details, while McKesson still had not confirmed the true scope of the theft.

    Activehealthexec.com
  4. Sep 1, 2026

    McKesson remained in the investigation phase with no confirmation of the full scope of stolen data.

    Activeinfosecurity-magazine.com
  5. Aug 31, 2026

    McKesson's SEC filing showed the intrusion was detected on August 25, 2026, and the company said its investigation was in its early stages with materiality not yet determined; ShinyHunters told BleepingComputer it used vishing calls to obtain employee credentials, then took over Okta single sign-on accounts to reach McKesson's Salesforce and Snowflake environments and pulled out roughly a terabyte of data over four days.

    Activehelpnetsecurity.com
  6. Aug 31, 2026

    Coverage clarified the McKesson breach is a separate incident from a concurrent cyberattack on medical device maker Boston Scientific, which disrupted remote monitoring for some implanted heart devices; the two attacks were being reported together but are not confirmed to be connected.

    Activetheregister.com
  7. Aug 31, 2026

    ShinyHunters publicly claimed the theft of 284 million patient records and demanded a 55 million dollar ransom within 72 hours; McKesson confirmed the incident and said it expects intermittent service degradation.

    Activemddionline.com
  8. Aug 28, 2026

    McKesson disclosed a cybersecurity incident involving unauthorized access to third party applications after ShinyHunters claimed responsibility.

    Emergingbleepingcomputer.com

Sources

Related reports