ShinyHunters claims 284 million McKesson patient records
McKesson, one of the largest US healthcare and pharmaceutical distributors, confirmed a cybersecurity incident involving unauthorized access to third party cloud applications and theft of data tied to a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. The extortion group ShinyHunters claims it stole records covering tens of millions to as many as 284 million patients and has demanded a ransom reported at about 55 million dollars. McKesson says it continues to operate across all business lines and believes there is no ongoing unauthorized activity, though customers may still see occasional service issues tied to the incident.
- Started
- Aug 28, 2026
- Latest activity
- Sep 2, 2026
- Attributed to
- ShinyHuntersSuspected
- Where
- United States
- Sectors
- Healthcare
- Scale
- one healthcare distributor
Current status
A September 3 report repeated McKesson's statement that the theft affected a subset of customers and that no ongoing unauthorized activity was believed to remain; no broader scope or closure was reported.
Contained: The attack has been stopped or blocked. Recovery and investigation are still running.
Who is behind it
McKesson has not named an attacker; ShinyHunters' account of vishing and Okta/Salesforce/Snowflake access, reported by BleepingComputer and TechCrunch, remains the group's own claim, not a McKesson or government confirmation.
Impact
Attackers gained unauthorized access to third-party cloud applications (reported by the attacker group as Okta, Salesforce, and Snowflake) used by McKesson and removed data. ShinyHunters claims records for tens of millions of patients, including sensitive details such as Social Security numbers, diagnoses, medications, and autopsy information, were stolen. McKesson has now confirmed theft occurred and narrowed the confirmed scope to a subset of customers in two business units, but has not confirmed the total number of people affected or the 284 million figure, and says it does not believe further customer action is required at this time.
What to do
Watch for an official notification from McKesson before taking any action.
Timeline
-
Sep 3, 2026
Cyber Defense Magazine reported McKesson's existing confirmation that data was stolen from a subset of customers and that the company believed there was no ongoing unauthorized activity. It reported no new victim count, leak, attribution, or closure.
Containedcyberdefensemagazine.com -
Sep 2, 2026
McKesson confirmed on its cybersecurity information center that unauthorized access and data exfiltration were tied to a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units; a company spokesperson said McKesson continues to operate across all business lines and believes there is no ongoing unauthorized activity in its systems, though it did not disclose how many people were affected.
Containeddigitalmarketreports.com -
Sep 1, 2026
ShinyHunters told reporters the stolen McKesson data covers tens of millions of patients and includes sensitive records such as autopsy details, while McKesson still had not confirmed the true scope of the theft.
Activehealthexec.com -
Sep 1, 2026
McKesson remained in the investigation phase with no confirmation of the full scope of stolen data.
Activeinfosecurity-magazine.com -
Aug 31, 2026
McKesson's SEC filing showed the intrusion was detected on August 25, 2026, and the company said its investigation was in its early stages with materiality not yet determined; ShinyHunters told BleepingComputer it used vishing calls to obtain employee credentials, then took over Okta single sign-on accounts to reach McKesson's Salesforce and Snowflake environments and pulled out roughly a terabyte of data over four days.
Activehelpnetsecurity.com -
Aug 31, 2026
Coverage clarified the McKesson breach is a separate incident from a concurrent cyberattack on medical device maker Boston Scientific, which disrupted remote monitoring for some implanted heart devices; the two attacks were being reported together but are not confirmed to be connected.
Activetheregister.com -
Aug 31, 2026
ShinyHunters publicly claimed the theft of 284 million patient records and demanded a 55 million dollar ransom within 72 hours; McKesson confirmed the incident and said it expects intermittent service degradation.
Activemddionline.com -
Aug 28, 2026
McKesson disclosed a cybersecurity incident involving unauthorized access to third party applications after ShinyHunters claimed responsibility.
Emergingbleepingcomputer.com
Sources
- McKesson discloses breach after ShinyHunters claims patient data theft BleepingComputer Aug 28, 2026
- Healthcare Giant McKesson Investigates Data Breach Incident Infosecurity Magazine Sep 1, 2026
- ShinyHunters claims it stole 284 million patient records from McKesson Help Net Security Aug 31, 2026
- McKesson confirms cybersecurity incident as hackers claim millions of patient records stolen Fierce Healthcare Aug 31, 2026
- McKesson investigating cybersecurity incident involving 'exfiltration of certain data' Healthcare IT News Aug 31, 2026 unverified
- Hackers say McKesson data breach exposed records from tens of millions of patients HealthExec Sep 1, 2026
- Healthcare cyberattacks hit pacemakers and millions of patient records The Register Aug 31, 2026
- Pacemaker monitoring disrupted as healthcare firms face cyberattacks Computing Sep 2, 2026 unverified
- ShinyHunters Threatens to Leak Millions of McKesson Records GovInfoSecurity Aug 31, 2026
- McKesson Confirms Data Breach as Attacker Deadline Looms SecurityWeek Aug 31, 2026
- McKesson confirms data theft in cyberattack involving third-party apps Yahoo Finance Sep 2, 2026
- McKesson Confirms Data Theft After ShinyHunters Claims Cyberattack Digital Market Reports Sep 2, 2026
- Multiple healthcare giants hit by data breaches affecting patient records, social security numbers, and even implanted cardiac devices TechRadar Pro Sep 1, 2026
- McKesson Responds to Third-Party App Compromise Amid $55 Million Extortion Threat Cyber Defense Magazine Sep 3, 2026 unverified