Skip to content
SECURITY ADVISORY

McKesson Data Breach: ShinyHunters Claims 284M Records

13 MINUTES | SEPTEMBER 3, 2026
Two medical professionals looking anxiously at a computer monitor with cybersecurity icons and text that reads "284M Records Stolen."

Key Takeaways

  • Extortion group ShinyHunters claims it exfiltrated roughly 284 million records from McKesson
    Corporation, one of the largest healthcare distributors in the US, spanning patient, employee, physician, and clinic data.
  • McKesson has confirmed a cybersecurity incident involving unauthorized access to third-party
    applications, with the investigation ongoing; it has not validated the actor’s figures.
  • The reported entry point was voice phishing (vishing) targeting employees, leading to compromised Okta single sign-on credentials and downstream access to Salesforce and Snowflake environments.
  • ShinyHunters is demanding $55,236,150 in ransom and says roughly 1TB of data was exfiltrated over four days (August 21–25, 2026).

A phone call may have opened the door to one of the largest alleged healthcare data thefts on record.

McKesson has confirmed that unauthorized access to third-party applications led to data exfiltration. ShinyHunters claims it carried out the intrusion through voice phishing, compromised Okta accounts, and access to Salesforce and Snowflake.

The group also claims it obtained approximately 284 million records and one terabyte of data. McKesson has not confirmed those figures or the full reported attack path.

Security teams should treat those details as allegations while paying close attention to the method. The reported sequence shows how one compromised identity can provide access to several connected applications without a disclosed software vulnerability.

This analysis separates confirmed information from attacker claims and outlines the identity controls healthcare and enterprise security teams should examine now.

What Has McKesson Confirmed?

McKesson disclosed the incident in an SEC Form 8-K.

The filing states that McKesson discovered a cybersecurity incident affecting its information systems on August 25, 2026. At the time of filing, the investigation was in its early stages.

McKesson had not determined that the incident was material or likely to have a material effect on its finances or operations.

The company later confirmed that unauthorized access to certain third-party applications resulted in data exfiltration associated with a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units.

McKesson also said it had reasonable assurance that no unauthorized activity remained in its systems.

The company has confirmed that:

  • It discovered a cybersecurity incident on August 25, 2026
  • Unauthorized access affected certain third-party applications
  • Data was exfiltrated
  • The activity involved specific business units and a subset of customers
  • Its investigation remained active when the updates were published

McKesson has not publicly confirmed the number of affected individuals, the exact data fields involved, or ShinyHunters’ full description of the intrusion.

What Does ShinyHunters Claim Happened?

ShinyHunters told security reporters that its operators used voice phishing, also known as vishing, against McKesson employees.

The group claims its callers impersonated IT support personnel and obtained access to employee identities. It says compromised Okta single sign-on accounts then provided access to Salesforce and Snowflake environments.

ShinyHunters also claims that it:

  • Exfiltrated approximately one terabyte of data
  • Accessed the environment between August 21 and August 25
  • Obtained roughly 284 million records
  • Collected patient, employee, physician, and clinic information
  • Demanded a ransom of approximately $55 million

TechCrunch reported that ShinyHunters provided screenshots and a sample of the allegedly stolen data. The publication said it verified a small subset against public records.

That verification does not confirm the entire dataset, the total number of records, or every part of the reported attack sequence.

An extortion group can possess authentic stolen information while overstating its reach or simplifying how an intrusion occurred. Until McKesson publishes further findings, the alleged details should remain attributed to ShinyHunters.

Confirmed Facts and Unverified Claims

Confirmed by McKesson

  • A cybersecurity incident was discovered on August 25
  • Certain third-party applications were accessed without authorization
  • Data was exfiltrated
  • The activity involved specific McKesson business units
  • A subset of customers was associated with the affected data
  • McKesson’s investigation is ongoing

Claimed by ShinyHunters or Reported by Media

  • Attackers used vishing against multiple employees
  • Employee Okta accounts were compromised
  • Salesforce and Snowflake environments were accessed
  • Approximately one terabyte of data was taken
  • The stolen material contained about 284 million records
  • ShinyHunters demanded approximately $55 million

Keeping these categories separate prevents an attacker’s statement from being presented as a completed forensic finding.

How the Reported Identity-to-SaaS Attack Path Works

The reported attack sequence resembles a documented enterprise data-theft technique.

Google Threat Intelligence has investigated campaigns in which attackers impersonated IT support staff, called employees, and persuaded them to approve actions that provided access to Salesforce.

In the cases Google examined, the attackers relied on social engineering and legitimate cloud features. They did not need to exploit a vulnerability in Salesforce.

A Caller Impersonates IT Support

The attacker contacts an employee and creates a believable technical problem.

The caller may mention an account issue, security update, device migration, failed login, or required identity verification. Knowledge of the company’s internal language can make the request appear legitimate.

Attackers may also use a look-alike domain to support the impersonation.

The Attacker Captures or Changes an Authenticator

The caller attempts to obtain credentials, capture a one-time code, trigger an MFA approval, or guide the employee through an account recovery process.

An attacker may also convince a help-desk employee to reset a password or enroll a new authentication factor.

Once the attacker has a valid session, the activity may appear to come from a legitimate employee.

SSO Extends Access to Connected Applications

Single sign-on allows employees to access multiple applications through one identity provider.

This arrangement improves usability, but it can increase the reach of a compromised account. Depending on the assigned permissions, one identity may provide access to CRM records, support cases, data warehouses, email, and administrative tools.

The reported McKesson data breach shows why SSO security must include controls that continue after authentication.

Legitimate Features Support Data Exfiltration

Salesforce, Snowflake, and other cloud platforms provide exports, APIs, connected applications, bulk queries, and data-loading tools for legitimate work.

An attacker with valid permissions may use those features to collect large volumes of data without installing malware.

This activity can resemble an unusually active employee. Detecting it requires identity monitoring, SaaS audit logs, and data-access analytics.

Google’s analysis of Salesforce-focused voice phishing recommends controlling connected applications, restricting Data Loader access, reviewing permission sets, and applying trusted network ranges.

Does 284 Million Records Mean 284 Million Patients?

No. The claimed figure refers to records, not confirmed unique patients.

A record is usually a database row, file entry, or application object. One person can appear in numerous records related to appointments, prescriptions, invoices, claims, shipments, support messages, and clinical notes.

A database containing 284 million rows could therefore represent far fewer than 284 million people.

This distinction does not reduce the seriousness of the alleged exposure. Detailed healthcare and identity information can create substantial privacy, fraud, and social engineering risks even when the number of affected individuals is lower.

However, organizations should not describe the incident as affecting 284 million patients unless McKesson confirms that number.

The same standard applies to the reported data types. ShinyHunters claims the stolen information includes personally identifiable information and protected health information. McKesson had not validated the specific fields in its available disclosures.

What Information Was Allegedly Exposed?

According to ShinyHunters, the dataset includes several categories of sensitive information.

Identity and Contact Information

The group claims the data contains:

  • Full names
  • Home addresses
  • Dates of birth
  • Phone numbers
  • Email addresses
  • Social Security numbers

Healthcare Information

The alleged healthcare records include:

  • Patient identification numbers
  • Medical record numbers
  • Medicaid numbers
  • Diagnoses
  • Allergies
  • Medications
  • Disabilities
  • Physician notes
  • Appointment information

Prescription and Billing Information

ShinyHunters also claims the dataset contains medication orders, invoices, delivery addresses, and shipment details.

Employee and Business Information

The group says it obtained employee contact details, job information, physician records, clinic data, and Salesforce support cases.

These categories remain allegations unless McKesson confirms them. Security teams should avoid treating the list as a final breach notification.

Why the McKesson Data Breach Matters to Healthcare Organizations

Healthcare data can support highly convincing fraud.

A criminal with access to personal and medical details can impersonate a pharmacy, insurance company, clinic, medical supplier, or billing department. The attacker can refer to familiar information to make an urgent request appear legitimate.

Possible scams may involve:

  • Prescription delays
  • Insurance verification
  • Unpaid medical claims
  • Appointment changes
  • Medical-supply deliveries
  • Requests to confirm patient information
  • Fake credit-monitoring enrollment

Healthcare organizations connected to McKesson may also face vendor impersonation attempts. Attackers could pose as McKesson employees and request credential changes, payment updates, integration assistance, or emergency access.

The incident also raises concerns about interconnected healthcare systems. Data can move between providers, distributors, pharmacies, insurers, cloud platforms, and support systems. Each connection adds identities, tokens, permissions, and logs that security teams must manage.

What the Incident Means for Enterprise Identity Security

The practical lesson extends beyond security-awareness training.

Training can reduce risk, but attackers can target a new employee, contractor, executive assistant, or help-desk analyst handling a convincing request.

Identity systems must limit the damage that follows a successful social engineering attempt.

Account Recovery Is a Privileged Process

Password resets and MFA re-enrollment can transfer control of an account.

Help-desk personnel need a verification process that does not depend on information an attacker can obtain online or through stolen data.

High-risk recovery requests should require a verified secondary channel, an approved device, manager authorization, or documented escalation.

NIST’s Digital Identity Guidelines warn against authentication processes that expose customer service agents to social engineering.

Authentication Must Continue Beyond Login

A successful login should not provide unrestricted access to every connected application.

Sensitive systems need device checks, risk-based access policies, step-up authentication, and session controls.

Security teams should also be able to revoke active sessions across the identity provider and downstream SaaS platforms.

SaaS Permissions Determine the Breach Radius

Many users need permission to view records. Far fewer need bulk exports, unrestricted queries, API access, or the ability to approve connected applications.

These capabilities should be separated and granted only to approved roles.

Permissions assigned during a migration, integration, or urgent project can remain active after the work ends. Regular access reviews help identify and remove them.

Data Controls Limit the Impact of a Stolen Identity

Masking, tokenization, row-level restrictions, export limits, and data-loss controls reduce the amount of usable information available to a compromised account.

Identity security and data security should reinforce each other. A stolen account should not automatically expose every sensitive field.

Seven Identity Controls Security Teams Should Review

Healthcare and enterprise security leaders do not need to wait for McKesson’s final report to examine their own exposure.

1. Harden Help-Desk Verification

Require strong identity proofing for password resets, factor changes, device enrollment, and account recovery.

Apply stricter requirements to administrators, help-desk personnel, executives, and employees with access to regulated data.

2. Adopt Phishing-Resistant MFA

Move high-risk users to phishing-resistant authentication such as FIDO2 or WebAuthn.

Start with identity administrators and employees who can approve applications, modify authentication factors, or export sensitive data.

Sennovate’s guide to zero trust identity management and FIDO2 explains how enterprises can plan this transition.

3. Restrict Authenticator Enrollment

Generate alerts when users add authentication factors, recover accounts, register devices, or sign in shortly after a reset.

Consider a cooling-off period or manual review for high-value accounts when business operations allow it.

4. Review Federated Application Access

Map which applications each identity can reach through SSO.

Remove stale assignments and require additional authentication for sensitive systems or high-risk actions.

5. Separate Data Access From Data Export

Viewing data and exporting it should require different permissions.

Restrict bulk queries, report downloads, API tokens, connected applications, and data-loading tools. Alert on sudden increases in export activity.

6. Correlate Identity and SaaS Events

Send identity-provider events, Salesforce audit data, Snowflake access history, endpoint signals, and help-desk changes to the Security Operations Center.

A newly enrolled authentication factor followed by a large data export should trigger one connected investigation.

7. Test Session Revocation

Security teams should regularly test how quickly they can:

  • Disable a compromised account
  • Revoke active tokens
  • End downstream SaaS sessions
  • Remove unauthorized connected applications
  • Block further data exports
  • Preserve evidence for investigation

Sennovate’s identity and access management services help organizations assess, design, govern, and operate identity environments across leading platforms.

What Should Patients, Employees, and Partners Do?

People who receive a formal notice from McKesson should follow the instructions provided in that communication.

Until the company confirms the affected population and data types, individuals should remain cautious about messages that reference the incident.

Watch for unexpected calls, texts, or emails concerning:

  • Prescription or medication problems
  • Insurance verification
  • Unpaid claims
  • Appointment changes
  • Package deliveries
  • Credit monitoring
  • Requests for a Social Security number
  • Requests for a password or one-time code

Verify each request through a phone number, website, or portal you already trust. Do not rely on contact details provided in an unexpected message.

Organizations connected to McKesson should brief help-desk teams, customer service personnel, finance staff, and employees who manage vendor relationships. These teams may receive impersonation attempts related to the incident.

Frequently Asked Questions

Was McKesson Breached by ShinyHunters?

McKesson confirmed unauthorized access to third-party applications and data exfiltration. ShinyHunters claimed responsibility.

McKesson had not publicly attributed the incident to ShinyHunters in the disclosures reviewed for this article.

Did the McKesson Data Breach Affect 284 Million Patients?

That has not been confirmed.

ShinyHunters described approximately 284 million records. One person can appear in several database records, so the figure should not be treated as a count of unique patients.

Were Okta, Salesforce, or Snowflake Hacked?

No disclosed evidence shows that vulnerabilities in these platforms caused the incident.

ShinyHunters claims it used compromised identities to access McKesson’s cloud applications. McKesson had not confirmed this reported attack path at the time of writing.

What Is Vishing?

Vishing is voice phishing.

An attacker uses a phone call or voice message to impersonate a trusted person. The caller may attempt to obtain credentials, capture an authentication code, trigger an MFA approval, or manipulate an account recovery process.

Can MFA Prevent This Type of Attack?

MFA reduces risk, but some authentication methods can be relayed, approved under pressure, or replaced through an insecure recovery process.

Phishing-resistant methods such as FIDO2 and WebAuthn provide stronger protection. Secure recovery and enrollment controls remain necessary.

Why Are Healthcare Records Valuable to Attackers?

Healthcare records can contain identity, contact, insurance, financial, and medical information.

Criminals can use these details to create convincing scams, commit identity fraud, target patients, or pressure an organization during extortion negotiations.

Security Teams Can Act Before the Investigation Ends

The final scope of the McKesson data breach may change as the investigation continues. The control questions are already clear.

Who can reset an account? What evidence must they provide? Which applications can one SSO session access? Who can export large datasets? Can the SOC connect identity changes with unusual SaaS activity quickly enough to stop an active theft?

An identity program depends on secure recovery workflows, controlled SaaS permissions, useful telemetry, and tested response procedures.

Strengthen Identity Security With Sennovate

Sennovate helps healthcare and enterprise teams secure SSO, harden account recovery, and monitor cloud access before identity compromise becomes a data breach.

Talk to an Expert
CTA Graphic