McKesson, a major U.S. healthcare and pharmaceutical distribution company, has disclosed a cybersecurity incident involving unauthorized access to third-party applications and subsequent data theft. The extortion group ShinyHunters has claimed responsibility, alleging the exfiltration of approximately 284 million patient data records. McKesson discovered the incident on August 25, 2026, and its investigation is ongoing, with further coverage provided by Bleeping Computer.The incident at McKesson reportedly began with voice phishing (vishing) attacks targeting employees, leading to the compromise of Okta single sign-on accounts. Threat actors then allegedly used these credentials to access McKesson's Salesforce and Snowflake environments. ShinyHunters claims to have exfiltrated about 1 terabyte of data over four days, including names, addresses, dates of birth, Social Security numbers, medical record numbers, and other sensitive patient information. The group also claims to have accessed internal communications and data related to healthcare providers.McKesson has confirmed unauthorized access and data exfiltration from third-party applications and warned customers of potential intermittent service degradation. The company has not yet determined the materiality of the incident. This attack is part of a broader trend of data-theft attacks by ShinyHunters targeting the healthcare sector, with other notable victims including Medtronic and DentaQuest.Source: Bleeping Computer
Breach
McKesson discloses data breach after ShinyHunters claims theft of 284 million records
(Adobe Stock)
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
Related Terms
Attack VectorYou can skip this ad in 5 seconds
