The McKesson ShinyHunters data breach came to light on 25 August 2026, the day the company says it discovered the incident, with the extortion group claiming it had already spent four days quietly siphoning roughly 1TB of data from McKesson’s cloud environments. McKesson disclosed the incident in a Form 8-K filing with the US Securities and Exchange Commission, stating that its investigation remains in the early stages and that it has not yet determined whether the incident is material to its financial condition or results of operations.

In a separate notice to customers, McKesson confirmed that the attack involved third-party applications and the unauthorised access and exfiltration of data. The company said it had immediately activated its incident response protocols and engaged external cybersecurity experts. Customers were also warned they may experience intermittent service degradation believed to be connected to the attack, though McKesson said it was not proactively disconnecting systems within its environment.

How the McKesson ShinyHunters Data Breach Unfolded

ShinyHunters told BleepingComputer that the intrusion began with voice phishing, or vishing, social engineering attacks targeting multiple McKesson employees. The group said those attacks led to the compromise of multiple employees’ Okta single sign-on accounts. From there, the attackers accessed McKesson’s Salesforce and Snowflake environments, claiming to have fully compromised the Salesforce environment, including support cases.

BleepingComputer also learned from a separate source that the attackers used the domain mckesson[.]claims during the campaign. That domain matches a pattern documented by ReliaQuest’s Threat Research team, which had tracked ShinyHunters registering .claims domains incorporating targeted organisations’ names or abbreviations to impersonate their help desks and IT teams. ReliaQuest published its findings in a post that has since been deleted from X.

According to Obsidian Security, the attackers also established persistence through MFA changes as part of this attack pattern, a step that would make it considerably harder to evict them once initial access was secured. The tactic fits the broader picture of a group that is methodical about staying inside a target environment long enough to move laterally and exfiltrate at scale.

The scale claimed here is substantial. ShinyHunters says it exfiltrated data between 21 and 25 August and that the stolen Snowflake data contains approximately 284 million data records of patient-related information. The group later clarified to BleepingComputer that this figure represents a raw count of data records or lines, not a count of unique individuals, and that it has not fully analysed the data to determine how many distinct people are included.

What the Stolen Data Allegedly Contains

ShinyHunters claims the exfiltrated records include names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, and appointment and physician information. The group also claims the data contains information related to deceased and terminally ill patients, prescriptions and medication shipments, invoices, employee records, Salesforce data, internal communications, and information about healthcare providers and clinics using McKesson’s services.

BleepingComputer has not independently verified those claims. McKesson has not publicly disclosed which third-party applications were compromised, how the attackers gained initial access, or what categories of information were actually stolen.

After completing the exfiltration on 25 August, ShinyHunters says it contacted McKesson and demanded a ransom of $55,236,150, giving the company 72 hours to respond. According to the group, McKesson did not respond to or negotiate over the demand.

A Wider Campaign Against Healthcare Targets

The McKesson ShinyHunters data breach is not an isolated incident. Health-ISAC has warned healthcare organisations about increasing ShinyHunters attacks involving social engineering designed to compromise corporate accounts and gain access to cloud and SaaS platforms. Other healthcare technology companies the group has reportedly targeted include Medtronic, DentaQuest, iRhythm, OneMedical, and AdaptHealth.

The Salesforce angle is also worth contextualising. According to Huntress, in March 2026 Salesforce issued a security advisory warning of a known threat group exploiting misconfigurations in Salesforce Experience Cloud (Aura). That advisory preceded the McKesson incident by several months, raising questions about whether the specific configuration weaknesses flagged at the time had been fully remediated across enterprise deployments.

McKesson says it will provide additional information as its investigation develops. Updates are being published at McKesson‘s dedicated cybersecurity page.

Share.

Software engineer and video game uber-nerd.

Comments are closed.

Exit mobile version