AIO APEX

ShinyHunters claims 284 million patient records stolen from McKesson in vishing attack

BleepingComputer
Share:
ShinyHunters claims 284 million patient records stolen from McKesson in vishing attack

McKesson, one of the largest pharmaceutical distributors in the United States, disclosed a major cybersecurity incident on August 28, 2026, after the ShinyHunters extortion group claimed to have stolen 284 million patient data records through a sophisticated vishing (voice phishing) attack. The company filed an 8-K with the U.S. Securities and Exchange Commission the same day.

How the Attack Happened

ShinyHunters told BleepingComputer that attackers used voice phishing calls to trick multiple McKesson employees into surrendering their Okta single sign-on (SSO) credentials. With those credentials, they gained access to McKesson's Salesforce and Snowflake cloud environments. Between August 21 and August 25, 2026, the group claims to have exfiltrated approximately 1 terabyte of data before McKesson detected the intrusion.

What Was Stolen

According to ShinyHunters, the stolen data includes patient names, home addresses, dates of birth, phone numbers, email addresses, Social Security numbers, medical record numbers, Medicaid IDs, diagnoses, allergies, medications, hospice and terminal illness records, causes of death, and autopsy details. Employee records, internal communications, and prescription shipment data were also allegedly taken.

ShinyHunters initially claimed 284 million records, but later clarified that figure represents raw data lines — not necessarily 284 million unique individuals. The actual number of people affected remains unknown while McKesson's investigation continues.

The Ransom Demand

The group demanded $55,236,150 from McKesson with a 72-hour deadline. McKesson did not respond to or negotiate over the demand. In its SEC filing, the company stated it has not determined the incident to be material to its financial results, though it warned customers of intermittent service degradation.

Scale and Significance

If the breach claims are accurate, this would be one of the largest healthcare data breaches in U.S. history by raw record count. For context, the DentaQuest ransomware attack disclosed earlier in 2026 — itself the previous largest healthcare breach of the year — affected 15 million individuals. McKesson supplies medications and technology services to tens of thousands of pharmacies, hospitals, and clinics across the country, meaning patients of any provider using McKesson's systems could be affected.

What Patients Should Do

Security experts recommend that anyone who has received healthcare services from a provider using McKesson's platform remain alert to phishing emails, fraudulent medical billing, prescription-related scams, and identity theft attempts. McKesson's investigation is ongoing, and the company has set up a cybersecurity information center at mckesson.com/cybersecurity.

This story was first reported by BleepingComputer and CyberInsider, based on McKesson's SEC 8-K filing and direct communication with ShinyHunters.

Originally reported by BleepingComputer. Read the original article for additional details.

View original source
Share: