CSIDB logo
Incident

McKesson

Incident posture

Attack window
Aug 2026
Location
United States of America
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-31 17:34

Linked entities

Victim
McKesson
Threat actors
1 actor
Sources
2 sources

Timeline

Occurred
Aug 2026
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending

Summary

Healthcare and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming responsibility. The attackers reportedly conducted voice phishing attacks against employees to compromise Okta single sign-on accounts, which were then used to access the company's Salesforce and Snowflake environments. ShinyHunters claims to have exfiltrated approximately 1TB of data over four days, containing around 284 million data records of patient-related information, including names, addresses, Social Security numbers, medical record numbers, and medication details. The group demanded a ransom of approximately $55 million, which the company did not respond to or negotiate. The investigation remains ongoing, with intermittent service degradation reported but no material impact confirmed at the time of disclosure.

Motives

Detailed motive labels are available to members.

1 motive

TTPs

Detailed technique labels are available to members.

0 techniques

Description

On August 25, 2026, McKesson, a major U.S. healthcare and pharmaceutical distribution company, discovered a cybersecurity incident involving third-party applications and the unauthorized exfiltration of data. The company subsequently disclosed the incident through a Form 8-K filing with the U.S. Securities and Exchange Commission and through a dedicated webpage at www.mckesson.com/cybersecurity. In its SEC filing, McKesson stated that as of the date of filing, it had not determined the incident to be material or reasonably likely to have a material impact on its financial condition or results of operations. The company also issued a separate notice to customers confirming that the breach involved third-party applications and unauthorized access and data exfiltration.

Following discovery, McKesson activated its incident response protocols, launched an investigation, and engaged external cybersecurity industry experts to assist with the response. At the time of disclosure, McKesson had not publicly identified which third-party applications were compromised, how the attackers gained initial access, or what specific information was stolen. The company also warned customers that they might experience intermittent service degradation believed to be related to the attack, though it clarified that it was not proactively disconnecting systems within its environment. McKesson stated that its investigation remained in the early stages and that it would provide additional information as it developed a more complete understanding of the incident.

The ShinyHunters extortion group claimed responsibility for the attack, telling BleepingComputer that it gained access after conducting voice phishing, or vishing, social engineering attacks against multiple McKesson employees. ShinyHunters declined to share many technical details of the social engineering campaign, including the specific domain used, but another source identified the domain mckesson[.]claims as part of the operation. This domain matched a ShinyHunters campaign documented by ReliaQuest's Threat Research team, in which the group registered .claims domains containing the names or abbreviations of targeted companies to impersonate help desks and IT teams. According to ShinyHunters, the vishing attacks led to the compromise of multiple employees' Okta single sign-on accounts, which were then used to access the company's Salesforce and Snowflake environments.

ShinyHunters claimed to have fully compromised the Salesforce environment, including support cases, and to have stolen a significantly larger collection of patient-related data from Snowflake. The group stated that it exfiltrated approximately 1TB of data over four days, between August 21 and August 25, 2026. Within that dataset, ShinyHunters claimed there were roughly 284 million data records of patient-related information. The group later clarified to BleepingComputer that the 284 million figure represented a raw count of data records or lines rather than a count of unique individuals, and stated that it had not fully analyzed the stolen data and did not know how many unique people were represented.

According to ShinyHunters, the stolen Snowflake dataset included names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information, and physician information. The group also claimed the data contained information related to deceased and terminally ill patients, prescriptions and medication shipments, invoices, employee information, Salesforce records, internal communications, and details about healthcare providers and clinics using McKesson's services. BleepingComputer noted that it had not independently verified these claims, and McKesson had not publicly confirmed what information was stolen.

After completing the data theft on August 25, ShinyHunters contacted McKesson and demanded a ransom of $55,236,150, giving the company 72 hours to respond. According to ShinyHunters, McKesson did not respond to or negotiate over the ransom demand. The incident occurred amid a broader wave of data-theft attacks targeting healthcare and health technology organizations attributed to ShinyHunters, prompting warnings from Health-ISAC about increasing social engineering activity designed to compromise corporate accounts and gain access to cloud and SaaS platforms. Other healthcare technology companies recently targeted in similar ShinyHunters data-theft attacks included Medtronic, DentaQuest, iRhythm, OneMedical, and AdaptHealth.

Sources

Sources available to members: 2 sources.

CSIDB