Cyber & AI intelligence
Wasteland.
Briefs indexed2317
Issues25
Published Mondays07:30 CT
▣ Breach MCKESSON-SHINYHUNT 2026-08-29

McKesson: ShinyHunters Extortion and Third-Party Application Data Theft

"McKesson, one of the largest pharmaceutical distributors in the United States, has confirmed a cybersecurity incident involving unauthorized access to third-party applications and the exfiltration of data. The company…"

McKesson, one of the largest pharmaceutical distributors in the United States, has confirmed a cybersecurity incident involving unauthorized access to third-party applications and the exfiltration of data. The company discovered the incident on August 25, 2026, disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission on August 28, and says its investigation remains in the early stages. The ShinyHunters extortion group claims responsibility and says it took 284 million patient records. That figure comes entirely from the threat actor. McKesson has confirmed neither the number nor the identity of the attackers.

What Happened

The sequence is tight and well documented. CyberInsider (S6) reported the ShinyHunters claim first on August 28, saying it had reviewed data samples privately provided by the threat actor that "appear consistent with the types of information described in the data breach claims." McKesson then confirmed the incident to CyberInsider through a spokesperson and filed an 8-K with the SEC the same day, as reported by BleepingComputer (S1).

In its regulatory filing, McKesson stated that "as of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations." A separate customer notice confirmed that the incident "involved third-party applications and the unauthorized access and exfiltration of data," and that McKesson activated incident response protocols and engaged outside cybersecurity experts on discovery.

One operational detail is worth flagging for anyone downstream of McKesson's distribution network: the company warned customers they may experience intermittent service degradation believed to be related to the attack, while stating it was not proactively disconnecting systems within its environment. That is an unusual combination. It suggests degradation is a side effect of investigation and containment activity rather than a deliberate isolation decision.

McKesson has not publicly identified which third-party applications were involved. UndercodeNews (S7) reports that ShinyHunters claims it compromised employee accounts before pivoting into Salesforce and Snowflake environments and extracting roughly 1 TB of data over four days. That attack narrative is attributed to the threat actor and has not been corroborated by McKesson or by the established security press at time of writing.

What Was Taken

Here the accounts diverge sharply, and the honest answer is that nobody outside the investigation knows yet.

McKesson confirms only that data was accessed and exfiltrated from third-party applications. It has not characterised the data types, the volume, or the number of affected individuals.

ShinyHunters claims 284 million patient records. Both BleepingComputer (S1) and CyberInsider (S6) report that figure as the group's claim, with CyberInsider describing the alleged contents as identity and contact information including full names, home addresses, dates of birth and phone numbers, alongside medical, prescription and healthcare provider data.

The critical qualification comes from UndercodeNews (S7), which reports that ShinyHunters itself clarified the 284 million figure represents raw records or database lines rather than unique individuals, and that the group has not determined how many distinct people are represented. That distinction matters enormously. A pharmaceutical distribution and pharmacy technology platform generates multiple rows per patient per prescription fill. A 284 million row Snowflake extract could plausibly represent an order of magnitude fewer people. Because this qualification appears in a single OTHER-tier source, treat it as attributed rather than established, but treat the headline 284 million as a raw record count regardless. It is not a victim count.

For calibration on how ShinyHunters claims have converted to reality in adjacent healthcare cases: the group leaked approximately 7.1 million records from Baxter International in August 2026 (HIPAA Journal, S3), and the Exact Sciences data published after Abbott declined to pay contained 10.9 million unique email addresses (The Register, S4). Both are large. Neither is anywhere near 284 million.

Why It Matters

This is not an isolated incident. It is the latest and largest entry in a campaign that Health-ISAC formally warned the sector about a month ago.

On July 24, 2026, Health-ISAC issued an advisory on an observed increase in successful ShinyHunters attacks against healthcare and medical technology organizations (BleepingComputer, S2). The victim list since then reads as a campaign, not a coincidence: Abbott's Cancer Diagnostics business, disclosed July 16, with data dumped after the company declined to pay (S4, S8); Baxter International, disclosed August 13 and leaked August 19 after negotiations apparently failed (S3); and now McKesson, discovered August 25. Every one of these disclosures used near identical language about "unauthorized activity within certain third-party applications."

The strategic significance is the target selection. McKesson is not a hospital. It is a distributor and technology provider sitting upstream of an enormous number of pharmacies, hospitals, clinics and physician practices. Data aggregated at that layer covers patients who have no direct relationship with McKesson and have never heard of it. That is precisely why a raw record count in the hundreds of millions is not implausible for the platform, even if the unique individual count is far lower.

Note also the divergence in how these incidents get framed. Victims consistently emphasise no operational impact, no encryption, no material financial effect. ShinyHunters consistently frames it as a failed ransom negotiation, telling Abbott it "should've paid the ransom" (S4). Both can be true simultaneously. Pure exfiltration extortion is designed to produce exactly this shape: minimal operational damage, maximum disclosure liability.

For contrast on the slower burn, the MCBS breach (SecurityWeek, S5) shows where these cases land. A September 2025 intrusion at a medical billing company, four days of attacker access, and a final HHS-confirmed count of 1,261,464 individuals across seven named healthcare organizations. The confirmed number arrived roughly a year after the intrusion. Expect a similar lag before McKesson's real figure is known.

The Attack Technique

McKesson has not disclosed an initial access vector. But the Health-ISAC advisory (S2) and the confirmed details from the Abbott case (S4, S8) describe a repeatable chain that defenders should assume until McKesson says otherwise.

The chain starts with voice phishing. Attackers call employees or helpdesk personnel and manipulate them into resetting passwords, changing multifactor authentication methods, or enrolling a new device. Abbott confirmed publicly that its intrusion began with a vishing attack, and ShinyHunters told BleepingComputer it targeted several Abbott employees in mid-June and compromised a corporate Microsoft Entra single sign-on account (S8).

From there the SSO dashboard does the work. Once inside Okta, Microsoft Entra or Google SSO, the attacker sees a menu of every SaaS application that user can reach: Salesforce, Microsoft 365, SharePoint, DocuSign, Slack, Atlassian, Dropbox, Google Drive. As BleepingComputer puts it, the SSO dashboard becomes a springboard to a company's cloud data. ShinyHunters has also historically abused OAuth tokens obtained through compromises of third-party integration partners to reach Salesforce and Snowflake tenants directly (S2).

Two things follow. First, "third-party applications" in these disclosures does not necessarily mean a vendor was breached. It frequently means the company's own SaaS tenants were accessed with the company's own valid credentials. Second, this is not a malware problem. Abbott stressed its incident was "not an encryption malware event." Endpoint detection tuned for ransomware payloads will not see any of this.

What Organizations Should Do

  1. Harden the helpdesk before hardening anything else. Require verified out-of-band identity proofing for any password reset, MFA method change, or new device enrollment. This is the single control that breaks the documented ShinyHunters chain at step one. Written policy is not enough; test it with your own social engineering exercises.
  2. Enforce phishing-resistant MFA and lock down enrollment. FIDO2 or hardware-backed authenticators for all privileged and SaaS-connected accounts. Treat MFA enrollment and reset events as high-severity security events with alerting, not as routine IT tickets.
  3. Audit every OAuth grant and SaaS integration. Inventory what third-party applications are connected to your Salesforce, Snowflake, Microsoft 365 and Google Workspace tenants, what scopes they hold, and who authorised them. Revoke anything unused. Rotate tokens on any integration you cannot fully account for.
  4. Instrument SaaS data egress, not just endpoints. Alert on bulk export, unusual report generation, and large query volume in Salesforce and Snowflake. ShinyHunters allegedly moved 1 TB over four days at McKesson; that pattern is detectable in platform logs if anyone is watching them. Enable and centralise those logs now if you have not.
  5. Constrain the blast radius of a single SSO account. Apply least privilege to SaaS application assignment, require step-up authentication for bulk data operations, and consider IP or device-conditional access for high-value data platforms.
  6. Assume you are downstream. If your organization uses McKesson pharmacy, distribution or technology services, monitor mckesson.com/cybersecurity for updates, ask your account contacts directly which applications were involved, and begin scoping your own breach notification obligations before a record count is published rather than after.

Treat every claimed figure in this incident as provisional. McKesson's investigation is days old, the 284 million number is an unverified attacker claim about raw database rows, and the pattern from Baxter, Abbott and MCBS suggests the confirmed count will arrive months from now and look materially different.

Sources: McKesson discloses breach after ShinyHunters claims patient data theft | Health-ISAC warns of rising ShinyHunters data theft attacks on heal... | ShinyHunters Leaks 7.1 Million Baxter International Records | ShinyHunters called cancer diagnostics biz and tricked staffers int... | MCBS Data Breach Affects 1.2 Million Individuals - SecurityWeek | ShinyHunters claims McKesson data breach exposing 284 million patie... | McKesson Cyberattack Sparks New Healthcare Security Crisis as Shiny... | Medical giant Abbott investigates two cyber incidents as ShinyHunte...