Close Menu
Mozbot
    Facebook X (Twitter) Instagram
    Button
    MozbotMozbot
    Facebook X (Twitter) Instagram YouTube
    • About us
    • Technology
    • Gadgets
    • Apps & Software
      • Computing
    • News
    • Contact Us
    • Article Submissions
    Mozbot
    Home » News » McKesson ShinyHunters Data Breach Exposes 284 Million Patient Records
    Technology

    McKesson ShinyHunters Data Breach Exposes 284 Million Patient Records

    Gary BehanBy Gary Behan04/09/2026No Comments4 Mins Read
    Facebook Twitter Pinterest LinkedIn Reddit WhatsApp Email
    McKesson ShinyHunters data breach
    Share
    Facebook Twitter Pinterest Reddit WhatsApp Email

    The McKesson ShinyHunters data breach came to light on 25 August 2026, the day the company says it discovered the incident, with the extortion group claiming it had already spent four days quietly siphoning roughly 1TB of data from McKesson’s cloud environments. McKesson disclosed the incident in a Form 8-K filing with the US Securities and Exchange Commission, stating that its investigation remains in the early stages and that it has not yet determined whether the incident is material to its financial condition or results of operations.

    In a separate notice to customers, McKesson confirmed that the attack involved third-party applications and the unauthorised access and exfiltration of data. The company said it had immediately activated its incident response protocols and engaged external cybersecurity experts. Customers were also warned they may experience intermittent service degradation believed to be connected to the attack, though McKesson said it was not proactively disconnecting systems within its environment.

    How the McKesson ShinyHunters Data Breach Unfolded

    ShinyHunters told BleepingComputer that the intrusion began with voice phishing, or vishing, social engineering attacks targeting multiple McKesson employees. The group said those attacks led to the compromise of multiple employees’ Okta single sign-on accounts. From there, the attackers accessed McKesson’s Salesforce and Snowflake environments, claiming to have fully compromised the Salesforce environment, including support cases.

    BleepingComputer also learned from a separate source that the attackers used the domain mckesson[.]claims during the campaign. That domain matches a pattern documented by ReliaQuest’s Threat Research team, which had tracked ShinyHunters registering .claims domains incorporating targeted organisations’ names or abbreviations to impersonate their help desks and IT teams. ReliaQuest published its findings in a post that has since been deleted from X.

    According to Obsidian Security, the attackers also established persistence through MFA changes as part of this attack pattern, a step that would make it considerably harder to evict them once initial access was secured. The tactic fits the broader picture of a group that is methodical about staying inside a target environment long enough to move laterally and exfiltrate at scale.

    The scale claimed here is substantial. ShinyHunters says it exfiltrated data between 21 and 25 August and that the stolen Snowflake data contains approximately 284 million data records of patient-related information. The group later clarified to BleepingComputer that this figure represents a raw count of data records or lines, not a count of unique individuals, and that it has not fully analysed the data to determine how many distinct people are included.

    What the Stolen Data Allegedly Contains

    ShinyHunters claims the exfiltrated records include names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, and appointment and physician information. The group also claims the data contains information related to deceased and terminally ill patients, prescriptions and medication shipments, invoices, employee records, Salesforce data, internal communications, and information about healthcare providers and clinics using McKesson’s services.

    BleepingComputer has not independently verified those claims. McKesson has not publicly disclosed which third-party applications were compromised, how the attackers gained initial access, or what categories of information were actually stolen.

    After completing the exfiltration on 25 August, ShinyHunters says it contacted McKesson and demanded a ransom of $55,236,150, giving the company 72 hours to respond. According to the group, McKesson did not respond to or negotiate over the demand.

    A Wider Campaign Against Healthcare Targets

    The McKesson ShinyHunters data breach is not an isolated incident. Health-ISAC has warned healthcare organisations about increasing ShinyHunters attacks involving social engineering designed to compromise corporate accounts and gain access to cloud and SaaS platforms. Other healthcare technology companies the group has reportedly targeted include Medtronic, DentaQuest, iRhythm, OneMedical, and AdaptHealth.

    The Salesforce angle is also worth contextualising. According to Huntress, in March 2026 Salesforce issued a security advisory warning of a known threat group exploiting misconfigurations in Salesforce Experience Cloud (Aura). That advisory preceded the McKesson incident by several months, raising questions about whether the specific configuration weaknesses flagged at the time had been fully remediated across enterprise deployments.

    McKesson says it will provide additional information as its investigation develops. Updates are being published at McKesson‘s dedicated cybersecurity page.

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Email
    Previous ArticleNVD Enrichment Backlog Leaves Defenders Racing to Fill the Gaps
    Next Article Brave Browser Email Aliases Shield Real Addresses From Hackers and Spam
    Gary Behan

    Software engineer and video game uber-nerd.

    Related Posts

    ChatGPT Writing Style Feature Learns Your Voice From Gmail and Slack

    13/09/2026

    N-able Issues Emergency Fix for N-central RCE Vulnerability Under Active Scrutiny

    13/09/2026

    GPT-6 Astra Plus Rollout Begins, but Check Work First

    13/09/2026

    ASCII Smuggling Phishing Campaign Hid Lures Inside Millions of Finance Emails

    12/09/2026

    ClickFix EtherHiding Blockchain Attack Hits 5,400 Sites Across 2,200 Organisations

    12/09/2026

    OpenAI rogue AI disclosure gap laid bare by wiki hijacking incident

    12/09/2026
    Add A Comment

    Comments are closed.

    Categories
    • Apps & Software
    • Artificial Intelligence
    • Business
    • Computing
    • Education
    • Energy
    • Featured
    • Finance
    • Gadgets
    • Gaming
    • Health and Safety
    • Home
    • Lifestyle
    • Marketing
    • Medical
    • News
    • NFT
    • Opinions
    • Social
    • Technology
    • Travel & Tourism
    Mozbot
    Facebook X (Twitter) Instagram Pinterest
    © 2026 M0ZBOT. All Rights Reserved.

    Type above and press Enter to search. Press Esc to cancel.