Cyber & AI intelligence
Wasteland.
Briefs indexed2904
Issues29
Published Mondays07:30 CT
▣ Breach MCKESSON-PATIENT-D 2026-09-28

McKesson: ShinyHunters Steals Patient Data in Extortion Attack

"McKesson Corporation, the Texas-based distributor that handles roughly one-third of pharmaceuticals used in North America, has confirmed that attackers got into third-party cloud applications and stole data. The company…"

McKesson Corporation, the Texas-based distributor that handles roughly one-third of pharmaceuticals used in North America, has confirmed that attackers got into third-party cloud applications and stole data. The company says the data belongs to a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. The ShinyHunters extortion group has claimed responsibility and says it took 284 million rows of patient data. McKesson has not publicly named the attacker. It has also not said how many people are affected. Troy Hunt of HaveIBeenPwned has found 6.4 million unique email addresses in the data attributed to the breach, as reported by the HIPAA Journal. Morning Overview reports that ShinyHunters is demanding $55 million. McKesson has not confirmed that figure, and none of the established security outlets reviewed here repeat it, so treat it as unverified.

What Happened

McKesson says it discovered the incident on August 25, 2026. It disclosed the incident in a Form 8-K filed with the U.S. Securities and Exchange Commission, which lists August 25 as the date of the earliest event reported. Accounts differ on the filing date. Morning Overview says the disclosure was made on August 25. BleepingComputer and CyberScoop place the public disclosure on Friday, August 28, the same day CyberInsider first reported the breach and ShinyHunters added McKesson to its Tor-based leak site.

According to researchers cited by CyberScoop, the main data theft was already over by the time McKesson detected it. The intrusion ran for four days starting August 21. Morning Overview, citing BleepingComputer's reporting, gives the exfiltration window as roughly August 21 to August 25.

McKesson released its public statements in stages:

McKesson has declined to answer questions about ShinyHunters' claims (CyberScoop). It has not publicly identified which third-party platforms were involved (BleepingComputer).

What Was Taken

Volume: the figures vary by source and measure different things

Data types McKesson confirmed on September 8 (per the HIPAA Journal)

Every record likely includes names, addresses, phone numbers, email addresses, patient IDs and dates of birth. Records may also include one or more of the following:

Attacker claims beyond that list

ShinyHunters told TechCrunch it also took allergy information, patient notes, and McKesson employee data such as home addresses. TechCrunch says it verified a small subset of the sample the group shared.

McKesson says it will offer free credit monitoring and identity protection to affected individuals.

Why It Matters

This is a combined PHI and financial data exposure at a company that sits in the middle of the U.S. drug supply chain. McKesson reported $403.4 billion in revenue for the year ending in March (CyberScoop). The records mix clinical detail, government insurance IDs, Social Security numbers and payment card data. That combination is very useful for medical identity fraud, insurance fraud and targeted phishing of patients, especially oncology patients.

The attack also fits a pattern. ShinyHunters has spent the past two years running large data-theft extortion campaigns that do not use encryption. The group gets into SaaS and cloud data platforms, takes the data and threatens to leak it. It does not need to disrupt operations to apply pressure. McKesson's systems kept running, which is why an extortion-only model works for the attacker: there is no outage to recover from, only a data leak to stop. CyberScoop notes that the group is increasingly targeting the healthcare sector.

For defenders, the takeaway is that McKesson's own infrastructure was not directly breached. The attackers got in through its identity provider and the cloud data platforms connected to it. Perimeter and endpoint controls did not cover that path.

The Attack Technique

The sources agree that the attackers got in by tricking people, not by exploiting software flaws. The level of detail varies:

This matches ShinyHunters' known methods: social engineering against help desks and employees, abuse of SSO, and bulk exports from SaaS platforms. The specific Okta and vishing details come through a lower-tier source citing BleepingComputer. Treat them as strongly indicated but not confirmed by McKesson.

Indicator: mckesson[.]claims (spoofed credential-phishing domain, per Morning Overview)

What Organizations Should Do

  1. Harden identity provider (IdP) sign-in and recovery against vishing. Require phishing-resistant MFA (FIDO2 or passkeys) for all Okta or other IdP access. Require help desks to verify callers out-of-band before any password or MFA reset. Tell staff plainly that IT will never ask for credentials or MFA approvals over the phone.
  2. Watch for lookalike domains. Monitor registrations of lookalike domains that combine your brand with industry terms (for example .claims, -sso, -okta). Block them at DNS and email gateways, and pursue takedowns quickly.
  3. Lock down SaaS data platforms. For Snowflake and Salesforce, enforce network policies or IP allowlists and require SSO with device trust. Remove local accounts that bypass SSO, and tightly limit bulk export and API permissions.
  4. Alert on large or unusual data pulls. Send Snowflake query and access history and Salesforce Event Monitoring logs to your SIEM. Alert on unusually large result sets, new client applications, logins from unfamiliar locations, or sessions that follow a recent MFA change. McKesson took four days to detect the theft.
  5. Review OAuth apps and sessions linked to your IdP. Audit connected apps and API tokens, and revoke any that are unused or have excessive permissions. Make sure revoking a user's IdP session also ends their downstream SaaS sessions.
  6. Prepare for a data-theft extortion scenario. Have legal, HIPAA notification and communications plans that assume no encryption and no outage. The attacker's leverage is the threat to publish stolen PHI, and the notification deadline starts from when you discover the breach, not when the attacker contacts you.

Sources: Hackers steal millions of patient records from health giant McKesso... | mck-20260825 | McKesson discloses breach after ShinyHunters claims patient data theft | Hackers claim millions of patient records stolen during data breach... | McKesson confirms data exfiltration in cyber incident | McKesson Cyberattack: Stolen Data Includes 6.4 Million ... | McKesson Confirms Data Breach as Attacker Deadline Looms - Security... | McKesson copes with fallout from data theft extortion attack Cyber...