"About 284 million data records of patient-related information," the extortion group ShinyHunters told BleepingComputer — a raw-records figure the group later clarified was not a count of unique individuals.
McKesson's disclosure and timeline
McKesson confirmed a cybersecurity incident in a Form 8-K filed with the U.S. Securities and Exchange Commission after CyberInsider first reported the breach. The company says it discovered the incident on August 25, 2026, and that its investigation remains in the early stages. In the filing McKesson said it has "not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations."
McKesson directed stakeholders to an incident page at www.mckesson.com/cybersecurity and said it immediately activated incident response protocols and engaged external cybersecurity experts. The company also warned customers they may experience intermittent service degradation believed to be related to the attack and said it was not proactively disconnecting systems within its environment.
ShinyHunters' claims and ransom demand
The extortion group ShinyHunters told BleepingComputer it carried out the attack and claimed to have exfiltrated roughly 1 TB of data between August 21 and August 25. The group said the stolen Snowflake data contains approximately 284 million data records, a figure it described as a raw count of lines rather than a count of unique people; ShinyHunters said it had not fully analyzed the data and did not know how many unique individuals, if any, are represented.
ShinyHunters provided a long list of allegedly stolen fields: names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information, and physician information. The group also claimed the haul included information related to deceased and terminally ill patients, prescriptions and medication shipments, invoices, employee information, Salesforce records and internal communications, and healthcare providers and clinics using McKesson's services. BleepingComputer has not independently verified these claims, and McKesson has not publicly disclosed what information was taken.
After completing the alleged theft on August 25, ShinyHunters said it contacted McKesson and demanded a $55,236,150 ransom, giving the company 72 hours to respond. According to the threat actor, McKesson did not respond to or negotiate over the demand.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAlleged access path: vishing, Okta single sign-on, Salesforce and Snowflake
ShinyHunters told BleepingComputer it used voice phishing (vishing) social engineering against multiple McKesson employees to gain access. The group claims the vishing attacks led to compromise of multiple employees' Okta single sign-on accounts, which were then used to access Salesforce and Snowflake environments. The threat actor also said it fully compromised the Salesforce environment, including support cases, and that the larger set of patient-related information came from Snowflake.
BleepingComputer reported that another source indicated the attackers used the domain mckesson[.]claims as part of the campaign. That domain pattern matches ReliaQuest's tracking of a wider ShinyHunters campaign registering .claims domains incorporating targeted organizations' names or abbreviations to impersonate help desks and IT teams. ReliaQuest documented the campaign in a now-deleted post on X.
Service impact, investigative scope, and what McKesson has not disclosed
McKesson confirmed the incident involved third‑party applications and the unauthorized access and exfiltration of data but has not named which third‑party applications were compromised, how the attackers gained access, or what specific data was stolen. The company said its investigation is ongoing "to determine the full scope of the incident" and that it will provide additional information as it develops a more complete understanding.
McKesson's separate customer notice emphasized seriousness about security and privacy and said the company engaged "leading cybersecurity industry experts" to assist. Aside from the intermittent service degradation warning, McKesson stated it was not proactively disconnecting systems within its environment.
What this means for technologists, Health-ISAC, and patients
- Technologists and security teams: The reported use of vishing to obtain Okta credentials and subsequent access to cloud services like Salesforce and Snowflake underscores a pathway from social engineering to cloud compromise; defenders will watch whether the ongoing McKesson investigation confirms these control failures and which third‑party applications were involved.
- Health-ISAC and healthcare cyber defensers: Health-ISAC had recently warned of increasing ShinyHunters attacks that use social engineering to compromise corporate accounts and access cloud and SaaS platforms; the McKesson claims fit that pattern and may prompt further advisories to member organizations.
- Patients and healthcare providers using McKesson services: While the extortion group lists extensive categories of allegedly stolen data, McKesson has not confirmed the contents or scope; patients and providers will look for company notices and any required regulatory notifications as the investigation develops.
McKesson's public record so far is a confirmation of unauthorized access, an active but early-stage investigation, and a denial that it has yet identified material financial impact. The incident joins a string of ShinyHunters-attributed attacks against healthcare and health-technology organizations, and it raises immediate questions about credential security, third‑party application risk, and how cloud-hosted patient data is protected. McKesson and independent researchers will determine in the coming days whether the group's claims — including the 1 TB exfiltration and the 284 million raw-record count — hold up under forensic scrutiny.
Source: BleepingComputer — McKesson discloses breach after ShinyHunters claims patient data theft




