McKesson discloses breach after ShinyHunters claims patient data theft
McKesson discloses breach after ShinyHunters claims patient data theft. McKesson says 284 million patient data records were stolen.
Intelligence analysis by Qwen 2.5 (3B)

McKesson, a major U.S. healthcare company, has disclosed a cybersecurity incident involving a breach of patient data records by ShinyHunters.
A group called ShinyHunters stole lots of personal information from a big company that helps doctors and hospitals. They got into the company's computers and took away names, addresses, and other private stuff from about 284 million people.
Analysis
{"#ShinyHunters Attack":"ShinyHunters, an extortion group, claims responsibility for the breach, stating they gained access through voice phishing attacks. The group used the mckesson[.]claims domain to impersonate McKesson's help desk and IT teams. They compromised multiple employees' Okta single sign-on accounts, leading to the theft of patient data from Salesforce and Snowflake environments. The breach affected about 284 million data records, including names, addresses, dates of birth, Social Security numbers, and other personal information.","#McKesson's Response":"McKesson discovered the incident on August 25, 2026, and has not yet determined the full scope of the breach. The company has not publicly disclosed which third-party applications were compromised, how the attackers gained access, or what information was stolen. McKesson has warned customers of potential service degradation and is investigating the incident further.","#Implications":"The breach underscores the importance of robust cybersecurity measures and the need for continuous monitoring and incident response protocols. It also highlights the risks associated with social engineering attacks and the potential for attackers to gain access through compromised accounts."}
Key points
- McKesson disclosed a breach involving 284 million patient data records stolen by ShinyHunters.
- The breach occurred through a combination of social engineering attacks and compromised accounts.
- McKesson is investigating the incident and has not yet determined the full scope of the breach.
- The company has warned customers of potential service degradation and is continuing its investigation.
- The breach highlights the importance of robust cybersecurity measures and the need for continuous monitoring and incident response protocols.
With increased cybersecurity measures, the risk of such attacks can be reduced in the future.
If the same attack happens again, it could lead to more personal information being stolen.



