McKesson Data Breach: Hackers Claim 284 Million Records Stolen, Demand $55 Million
Key Takeaways
- •McKesson first identified unauthorized access on August 25, 2026, and later disclosed the incident in an SEC filing.
- •ShinyHunters claims it exfiltrated about 284 million database rows, not a confirmed count of unique patients.
- •The alleged intrusion began with vishing calls that led to compromised credentials and hijacked Okta single sign-on accounts.
- •ShinyHunters says it demanded $55,236,150 and gave McKesson 72 hours to respond.
- •McKesson said it continues to operate and reported intermittent service degradation, but it did not disclose the number of affected individuals.

McKesson Data Breach: Hackers Claim 284 Million Records Stolen, Demand $55 Million
A major pharmaceutical distribution company has become the latest U.S. healthcare organization targeted by hackers seeking patient records. The McKesson data breach, disclosed on August 28, 2026, has prompted a ransom demand reportedly worth tens of millions of dollars and raised concerns over sensitive medical information that could affect millions of patients. Because McKesson sits in the middle of the healthcare supply chain, any breach involving its business and patient data has implications not just for the company itself, but also for the providers, clinics, and customers that rely on its distribution and services.
Key takeaways
McKesson detected unauthorized access to third-party applications on August 25, 2026, and disclosed the incident in an SEC filing.
The extortion group ShinyHunters claims it stole roughly 284 million data records from McKesson’s Snowflake and Salesforce environments — a figure representing database rows, not confirmed unique patients.
Hackers say they used vishing calls to trick employees and hijack Okta single sign-on accounts, then moved laterally into cloud systems over a four-day window between August 21 and August 25.
ShinyHunters demanded a ransom of $55,236,150 and gave McKesson 72 hours to respond; the company reportedly never did.
McKesson confirmed intermittent service degradation but declined to say how many people were affected or what ransom demand it received.
The Breach and ShinyHunters’ Claims
McKesson’s disclosure was brief and limited in detail, but it confirmed the central point of the incident: intruders gained access to third-party applications and removed data before the company detected the activity. The McKesson data breach was first identified internally on August 25, 2026, and the company told the Securities and Exchange Commission that its investigation was still “in its early stages.” McKesson also said it had not yet determined whether the incident was financially material.
McKesson chief information and technology officer Francisco Fraga told customers that the confirmed unauthorized access and data exfiltration affected “a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units.” He added that the company was not proactively disconnecting systems and did not believe customers needed to take action, while noting that the investigation was still ongoing.
How the Hackers Broke In
ShinyHunters, described as one of the most active target="_self">lookalike domain, mckesson[.]claims, built to impersonate the company’s internal help desk or IT team. Researchers at ReliaQuest had already been tracking a broader pattern of similar attacks using the “.claims” naming scheme across multiple targeted organizations.
According to the hackers, they used social engineering to trick employees into giving up credentials, then took over Okta single sign-on accounts. From there, ShinyHunters says it moved into McKesson’s Salesforce and Snowflake cloud environments, where much of the company’s patient and business data is stored.
What They Say They Stole
The scale of the alleged theft is what makes this case stand out. ShinyHunters told Bleeping Computer that it exfiltrated roughly one terabyte of data over four days, between August 21 and August 25, and that the Snowflake environment alone produced about 284 million data records. The group later clarified that this figure refers to raw database rows rather than a confirmed count of unique patients, and it said it had not fully analyzed the material to determine how many individuals are represented.
That distinction is important. It means the true scope of the McKesson data breach remains uncertain, even according to the hackers themselves, and McKesson has not released its own estimate.
ShinyHunters says the stolen material includes names, home addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment details, and physician information. The group also claims the files include records connected to deceased and terminally ill patients, prescription and medication shipment records, invoices, internal communications, and information related to healthcare providers and clinics that use McKesson’s services. TechCrunch reported that it verified a small sample of the leaked data against public records, though the broader claims have not been independently confirmed by McKesson or outside researchers.
In addition to patient records, the hackers say employee information, including home addresses, was also taken, widening the impact beyond McKesson’s customer base.
A $55 Million Ultimatum and McKesson’s Response
The attack appears to have been driven not only by theft, but also by extortion. ShinyHunters told Bleeping Computer that it contacted McKesson after finishing the data theft on August 25 and demanded an exact ransom of $55,236,150, giving the company 72 hours to respond. The group says McKesson never engaged with the demand.
Publicly, McKesson has maintained a limited response. Spokesperson Kristina Chang told TechCrunch that the company “continues to operate in all lines of business” and said McKesson does not believe there is ongoing unauthorized activity in its systems. The company confirmed that customers could experience intermittent service degradation linked to the incident, but it declined to answer questions about the ransom demand or the number of individuals affected.
That lack of disclosure is significant. When a company handling patient data at McKesson’s scale will not confirm how many people may be affected, patients, providers, and regulators are left without a clear picture of the exposure, and that uncertainty can remain long after the initial report.
A Widening Pattern of Healthcare Cyberattacks
McKesson is not an isolated case. It is the latest in a fast-moving wave of attacks against U.S. healthcare and medtech companies. A cyberattack hit medical device manufacturer Boston Scientific last week, causing significant disruption and taking much of its network offline, following an earlier incident at fellow device maker Stryker, where hackers allegedly used internal tools to remotely wipe thousands of employee devices.
Abbott Laboratories and Medtronic have also experienced cyberattacks in recent months. Data breaches have affected health tech firm TriZetto and electronic patient records provider CareCloud, each involving more than 3 million patients. ShinyHunters has also claimed responsibility for breaches at Amazon-owned One Medical and dental insurer DentaQuest, as well as attacks on Medtronic, iRhythm, and AdaptHealth.
Health-ISAC has warned healthcare organizations about the growing number of ShinyHunters attacks built around social engineering aimed at corporate accounts and cloud or SaaS platforms — the same playbook alleged in the McKesson case. For an industry that holds some of the most sensitive personal data available, the repeated use of this vishing-to-cloud-breach pattern keeps attention on account security, third-party access controls, and cloud monitoring across healthcare organizations.
FAQ
Who was responsible for the McKesson data breach?
The hacking group ShinyHunters claimed responsibility for the cyberattack, saying it gained access through vishing calls and social engineering aimed at McKesson employees.
What kind of data was stolen in the cyberattack on McKesson?
ShinyHunters claims it took roughly 284 million data records containing personal and protected health information, along with employee personal data such as home addresses. The figure reflects database rows rather than a confirmed number of unique patients.
How did the hackers access McKesson’s systems?
According to the hackers, vishing calls tricked employees into giving up credentials, which were then used to hijack Okta single sign-on accounts. From there, the attackers moved into McKesson’s cloud-hosted Salesforce and Snowflake environments to extract data.
Did McKesson pay the ransom demanded by the hackers?
McKesson declined to disclose details about any ransom payment. ShinyHunters says it demanded $55,236,150 with a 72-hour deadline and that McKesson never responded to the demand.
Article produced with the assistance of artificial intelligence and reviewed by the editorial team.