McKesson Corporation, the Texas-based distributor that handles roughly one-third of pharmaceuticals used in North America, has confirmed that attackers got into third-party cloud applications and stole data. The company says the data belongs to a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. The ShinyHunters extortion group has claimed responsibility and says it took 284 million rows of patient data. McKesson has not publicly named the attacker. It has also not said how many people are affected. Troy Hunt of HaveIBeenPwned has found 6.4 million unique email addresses in the data attributed to the breach, as reported by the HIPAA Journal. Morning Overview reports that ShinyHunters is demanding $55 million. McKesson has not confirmed that figure, and none of the established security outlets reviewed here repeat it, so treat it as unverified.
What Happened
McKesson says it discovered the incident on August 25, 2026. It disclosed the incident in a Form 8-K filed with the U.S. Securities and Exchange Commission, which lists August 25 as the date of the earliest event reported. Accounts differ on the filing date. Morning Overview says the disclosure was made on August 25. BleepingComputer and CyberScoop place the public disclosure on Friday, August 28, the same day CyberInsider first reported the breach and ShinyHunters added McKesson to its Tor-based leak site.
According to researchers cited by CyberScoop, the main data theft was already over by the time McKesson detected it. The intrusion ran for four days starting August 21. Morning Overview, citing BleepingComputer's reporting, gives the exfiltration window as roughly August 21 to August 25.
McKesson released its public statements in stages:
- 8-K filing: The company said the investigation was "in its early stages." It also said it "has not determined that the incident is material" to its financial condition or results.
- August 28 notice: McKesson confirmed unauthorized access to third-party applications and data exfiltration. It warned customers of "intermittent service degradation" but said it was not proactively disconnecting systems.
- August 29 update: Francisco Fraga tied the stolen data to the two business units. TechCrunch describes Fraga as chief technology officer and CyberScoop as chief information and technology officer. McKesson said it has "reasonable assurance of no ongoing unauthorized activity," that distribution centers remain operational, and that customers can keep using its systems.
- September 8 update: McKesson listed the categories of data likely exfiltrated, according to the HIPAA Journal.
McKesson has declined to answer questions about ShinyHunters' claims (CyberScoop). It has not publicly identified which third-party platforms were involved (BleepingComputer).
What Was Taken
Volume: the figures vary by source and measure different things
- Attacker claim: ShinyHunters says it took 284 million rows of patient data (BleepingComputer, SecurityWeek, HIPAA Journal, Morning Overview). The HIPAA Journal notes that this row count is unlikely to mean 284 million unique patients. ShinyHunters itself told TechCrunch it is unsure how many individuals are affected.
- Independent analysis: Troy Hunt found 6.4 million unique email addresses in the allegedly stolen data (HIPAA Journal). This is the most concrete independent figure available, but it counts email addresses, not affected patients.
- Data size: Morning Overview reports about 1 TB was exfiltrated, citing BleepingComputer.
- McKesson: The company has not disclosed a count of affected individuals.
Data types McKesson confirmed on September 8 (per the HIPAA Journal)
Every record likely includes names, addresses, phone numbers, email addresses, patient IDs and dates of birth. Records may also include one or more of the following:
- Health insurance details, including Medicaid and Medicare ID numbers
- Clinical data: dates of service, medical record numbers, providers, diagnoses, medications, test results, medical images, and care or treatment information
- Billing, claims and payment data, including credit and debit card numbers and banking information
- Social Security numbers and other identity-verification data
Attacker claims beyond that list
ShinyHunters told TechCrunch it also took allergy information, patient notes, and McKesson employee data such as home addresses. TechCrunch says it verified a small subset of the sample the group shared.
McKesson says it will offer free credit monitoring and identity protection to affected individuals.
Why It Matters
This is a combined PHI and financial data exposure at a company that sits in the middle of the U.S. drug supply chain. McKesson reported $403.4 billion in revenue for the year ending in March (CyberScoop). The records mix clinical detail, government insurance IDs, Social Security numbers and payment card data. That combination is very useful for medical identity fraud, insurance fraud and targeted phishing of patients, especially oncology patients.
The attack also fits a pattern. ShinyHunters has spent the past two years running large data-theft extortion campaigns that do not use encryption. The group gets into SaaS and cloud data platforms, takes the data and threatens to leak it. It does not need to disrupt operations to apply pressure. McKesson's systems kept running, which is why an extortion-only model works for the attacker: there is no outage to recover from, only a data leak to stop. CyberScoop notes that the group is increasingly targeting the healthcare sector.
For defenders, the takeaway is that McKesson's own infrastructure was not directly breached. The attackers got in through its identity provider and the cloud data platforms connected to it. Perimeter and endpoint controls did not cover that path.
The Attack Technique
The sources agree that the attackers got in by tricking people, not by exploiting software flaws. The level of detail varies:
- ShinyHunters' account (TechCrunch): The group says it tricked several employees into granting access using phishing and social engineering, then took data from McKesson's cloud-hosted Snowflake and Salesforce environments.
- Detailed attack chain (Morning Overview, citing BleepingComputer):
- Voice phishing (vishing) calls impersonating IT staff.
- A spoofed domain,
mckesson[.]claims, used to collect credentials. - Stolen credentials for McKesson's Okta identity system.
- Access through Okta single sign-on to Salesforce and Snowflake.
- Bulk exfiltration over roughly four days.
- McKesson's account: The company says only that "third-party applications" were involved.
This matches ShinyHunters' known methods: social engineering against help desks and employees, abuse of SSO, and bulk exports from SaaS platforms. The specific Okta and vishing details come through a lower-tier source citing BleepingComputer. Treat them as strongly indicated but not confirmed by McKesson.
Indicator: mckesson[.]claims (spoofed credential-phishing domain, per Morning Overview)
What Organizations Should Do
- Harden identity provider (IdP) sign-in and recovery against vishing. Require phishing-resistant MFA (FIDO2 or passkeys) for all Okta or other IdP access. Require help desks to verify callers out-of-band before any password or MFA reset. Tell staff plainly that IT will never ask for credentials or MFA approvals over the phone.
- Watch for lookalike domains. Monitor registrations of lookalike domains that combine your brand with industry terms (for example
.claims,-sso,-okta). Block them at DNS and email gateways, and pursue takedowns quickly. - Lock down SaaS data platforms. For Snowflake and Salesforce, enforce network policies or IP allowlists and require SSO with device trust. Remove local accounts that bypass SSO, and tightly limit bulk export and API permissions.
- Alert on large or unusual data pulls. Send Snowflake query and access history and Salesforce Event Monitoring logs to your SIEM. Alert on unusually large result sets, new client applications, logins from unfamiliar locations, or sessions that follow a recent MFA change. McKesson took four days to detect the theft.
- Review OAuth apps and sessions linked to your IdP. Audit connected apps and API tokens, and revoke any that are unused or have excessive permissions. Make sure revoking a user's IdP session also ends their downstream SaaS sessions.
- Prepare for a data-theft extortion scenario. Have legal, HIPAA notification and communications plans that assume no encryption and no outage. The attacker's leverage is the threat to publish stolen PHI, and the notification deadline starts from when you discover the breach, not when the attacker contacts you.
Sources: Hackers steal millions of patient records from health giant McKesso... | mck-20260825 | McKesson discloses breach after ShinyHunters claims patient data theft | Hackers claim millions of patient records stolen during data breach... | McKesson confirms data exfiltration in cyber incident | McKesson Cyberattack: Stolen Data Includes 6.4 Million ... | McKesson Confirms Data Breach as Attacker Deadline Looms - Security... | McKesson copes with fallout from data theft extortion attack Cyber...