Skip to content
SECURITY ADVISORY

McKesson Data Breach: ShinyHunters Claims 284M Records

10 MINUTES | SEPTEMBER 3, 2026
Two medical professionals looking anxiously at a computer monitor with cybersecurity icons and text that reads "284M Records Stolen."

Key Takeaways

  • ShinyHunters says it took about 284 million records from McKesson. That number counts database rows, not people.
  • McKesson has confirmed that data was stolen from third-party applications. Its September 8 update says the data likely includes names, contact details, dates of birth, insurance, medical, billing and payment information, and Social Security numbers.
  • The attackers say they phoned employees, took over their Okta single sign-on accounts, and used those accounts to reach Salesforce and Snowflake. McKesson has not confirmed this.
  • HaveIBeenPwned found 6.4 million unique email addresses in the data.

McKesson delivers roughly a third of the prescription medicines that reach hospitals, pharmacies, and clinics in North America. On August 25, 2026, it discovered that someone had accessed third-party applications it uses and taken data from them.

ShinyHunters, the extortion group behind several recent healthcare breaches, claimed the attack. The group says it took about 1TB of data over four days, and that the intrusion started with phone calls to McKesson employees.

McKesson has since confirmed the theft and the categories of data involved. It has not said how many people are affected or how the attackers got in. Below, we separate what McKesson has said from what ShinyHunters claims, then cover the identity controls that address this kind of attack.

Timeline

  • August 21 to 25: ShinyHunters says it exfiltrated data during this window.
  • August 25: McKesson discovers the incident.
  • August 28: McKesson announces the incident and files a Form 8-K with the SEC.
  • August 29: McKesson says orders are being accepted and its distribution centers are shipping as normal.
  • September 1: ShinyHunters’ deadline for McKesson to start negotiating. The group says McKesson never replied.
  • September 8: McKesson publishes initial findings on the types of data involved.
  • Mid-September: HaveIBeenPwned reports 6.4 million unique email addresses in the data.

What Has McKesson Confirmed?

McKesson’s Form 8-K says it discovered the incident on August 25 and that its investigation was at an early stage. At the time, it had not decided whether the incident was material to its finances or operations.

In later updates, the company said the affected data relates to a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. It also said its containment steps appear to have worked and it has seen no further unauthorized activity.

On September 8, McKesson said the stolen data likely includes names, addresses, phone numbers, email addresses, patient IDs, and dates of birth. Depending on the person, it may also include:

  • Health insurance details, including Medicaid and Medicare ID numbers
  • Medical information, including dates of service, medical record numbers, providers, diagnoses, medications, test results, medical images, and treatment details
  • Billing and payment information, including claim numbers, account numbers, credit and debit card numbers, and banking details
  • Social Security numbers

McKesson posts updates at mckesson.com/cybersecurity. It has not published the number of people affected, the total record count, or who was behind the attack.

What Does ShinyHunters Claim?

ShinyHunters told BleepingComputer that it ran voice phishing (vishing) calls against several McKesson employees. According to the group, those calls gave it access to employees’ Okta single sign-on accounts, which it then used to get into McKesson’s Salesforce and Snowflake environments. Cybernews reported that the group said it used a lookalike domain, mckesson[.]claims, during the calls.

The group also says it:

  • Took about 1TB of data between August 21 and 25
  • Collected roughly 284 million records covering patients, employees, physicians, and clinics
  • Asked McKesson for $55,236,150 and gave it 72 hours to respond

CyberInsider reviewed data samples the group supplied and said they matched the types of information described. That suggests the group holds real McKesson data. It does not confirm the record count or the attack path, and extortion groups often inflate both.

Confirmed Facts and Unverified Claims

Confirmed by McKesson

  • Incident discovered on August 25, 2026
  • Unauthorized access to certain third-party applications
  • Data was taken
  • Affected data relates to a subset of Oncology & Multispecialty and Medical-Surgical customers
  • Data likely includes contact details, dates of birth, patient IDs, insurance, medical, billing, payment, and Social Security information

Claimed by ShinyHunters or reported by media

  • Vishing calls to multiple employees
  • Compromised Okta single sign-on accounts
  • Access to Salesforce and Snowflake
  • About 1TB of data and 284 million records
  • A ransom demand of about $55 million
  • 6.4 million unique email addresses in the data (HaveIBeenPwned)

How the Reported Attack Path Works

The sequence ShinyHunters describes matches a pattern Google Threat Intelligence has documented in detail. In the campaigns Google examined, attackers never exploited a flaw in Salesforce. They talked their way in and then used the platform’s normal features.

1. The phone call

In similar campaigns, callers pose as IT support and raise a believable problem: a failed login, a required security update, a device migration. They often know internal team names and terms, and may send the employee to a site that looks like the company’s own.

2. Taking over the login

The goal is a working session. The caller may ask for a password and one-time code, push an MFA prompt and wait for the employee to approve it, or persuade the help desk to reset a password or register a new MFA device. After that, every action looks like it comes from a real employee.

3. Single sign-on extends the reach

Single sign-on lets one login open every application assigned to that user. For an attacker, one compromised account can mean CRM records, support cases, data warehouses, and admin consoles, depending on what that person was allowed to reach.

4. Exporting with built-in tools

Salesforce and Snowflake include exports, APIs, bulk queries, and data loaders because people need them for normal work. An attacker with the right permissions can use the same tools to pull large volumes of data without installing any malware. On the logs, it can look like an employee having a busy week.

Google recommends restricting connected apps, limiting who can use Data Loader, reviewing permission sets, and allowing access only from trusted network ranges.

Does 284 Million Records Mean 284 Million Patients?

No. A record is a row in a database. One patient can show up in hundreds of rows across appointments, prescriptions, invoices, claims, shipments, and notes.

The early numbers point to a much smaller group of people. HaveIBeenPwned found 6.4 million unique email addresses in the data, drawn from patients, staff, marketing lists, and other sources. That is not a head count either, since some people have no email on file and others have several. It does suggest the affected population is in the millions or tens of millions.

Until McKesson publishes a number, the incident should not be described as affecting 284 million patients.

What Information Was Exposed?

Confirmed by McKesson

  • Names, addresses, phone numbers, email addresses, patient IDs, and dates of birth
  • Insurance details, including Medicaid and Medicare IDs
  • Medical details, including diagnoses, medications, test results, images, and treatment information
  • Billing and payment details, including card numbers and banking information
  • Social Security numbers

Claimed only by ShinyHunters

  • Physician notes and allergy information
  • Prescription orders, delivery addresses, and shipment details
  • Employee contact and job details
  • Physician and clinic records
  • Salesforce support cases

The second list has not been verified. The first is already enough to support identity theft, insurance fraud, card fraud, and very convincing phishing.

Why This Matters to Healthcare Organizations

Anyone holding this data can make a scam call sound real. They can quote a patient’s medication, provider, or last appointment while claiming to be a pharmacy, insurer, clinic, or billing office. Expect messages about:

  • Delayed prescriptions or deliveries
  • Insurance verification
  • Unpaid claims or balances
  • Refunds or overpayments
  • Card or bank details that need “updating”
  • Credit monitoring sign-ups

McKesson’s customers should also expect calls and emails from people pretending to be McKesson staff, asking for password resets, payment changes, or help with an integration.

This is not an isolated case. Health-ISAC has warned members about ShinyHunters using social engineering to reach cloud and SaaS platforms, and the group has claimed attacks on Medtronic, DentaQuest, iRhythm, and AdaptHealth.

What This Means for Identity Security

Security awareness training helps, but a determined caller only needs one employee, contractor, or help desk analyst to believe them once. The controls that matter most are the ones that limit what happens after that.

Account recovery is a privileged action

Whoever can reset a password or add an MFA device can take over an account. Help desk staff need a verification process that doesn’t rely on facts an attacker can find online or in stolen data. NIST SP 800-63B specifically warns against recovery processes that leave support staff open to social engineering.

Checks should continue after login

A valid session should not open every connected application with no further questions. Sensitive apps need device checks, risk-based policies, and step-up authentication. The security team also needs to be able to kill active sessions in the identity provider and in each downstream SaaS app.

Permissions set the size of the breach

Plenty of people need to view records. Very few need bulk export, API access, or the right to approve connected apps. Access granted for a migration or one-off project tends to stay in place long after the work ends.

Data controls limit what one account can take

Masking, tokenization, row-level restrictions, and export limits reduce how much usable data a single stolen account can reach.

Seven Identity Controls to Review Now

1. Tighten help desk verification

Require strong identity proofing for password resets, MFA changes, and device enrollment. Apply the strictest rules to admins, help desk staff, executives, and anyone with access to regulated data.

2. Move high-risk users to phishing-resistant MFA

FIDO2 and WebAuthn cannot be read out over the phone or approved by mistake. Start with identity admins and people who can export sensitive data. Our guide to zero trust identity management and FIDO2 covers how to plan the move.

3. Watch authenticator changes

Alert when someone adds an MFA factor, recovers an account, registers a new device, or signs in soon after a reset. For high-value accounts, consider a waiting period or manual review.

4. Map what each identity can reach through SSO

List the applications each account can open, remove stale assignments, and require extra authentication for sensitive apps.

5. Separate viewing data from exporting it

Make export a separate permission. Restrict bulk queries, report downloads, API tokens, connected apps, and data loaders, and alert on sudden jumps in export volume.

6. Correlate identity and SaaS logs

Send identity provider events, Salesforce audit logs, Snowflake access history, and help desk changes to your SOC. A new MFA device followed by a large export should show up as one investigation, not two unrelated alerts.

7. Test how fast you can shut it down

Run the drill before you need it. Time how long it takes to:

  • Disable a compromised account
  • Revoke active tokens and downstream SaaS sessions
  • Remove unauthorized connected apps
  • Block further exports
  • Preserve logs for the investigation

Sennovate’s identity and access management services help organizations assess, design, and run identity programs across leading platforms.

What Should Patients, Employees, and Partners Do?

If you get a notice from McKesson, follow its instructions. Because card and banking details may be involved, check statements for charges you don’t recognize and consider a credit freeze.

Be wary of any unexpected call, text, or email about prescriptions, insurance, unpaid bills, deliveries, refunds, or credit monitoring, especially if it asks for your Social Security number, a password, or a one-time code. Call back using a number you already trust, not one given in the message.

Organizations that work with McKesson should brief their help desk, customer service, finance, and vendor management teams, since those are the people most likely to get impersonation attempts.

Got Questions? We've Got Answers.

Was McKesson breached by ShinyHunters?

McKesson has confirmed that data was stolen from third-party applications. ShinyHunters has claimed responsibility, but McKesson has not named the attacker. The group says McKesson did not respond to its ransom demand.

Did the breach affect 284 million patients?

What data has McKesson confirmed was exposed?

Were Okta, Salesforce, or Snowflake hacked?

What is vishing?

Would MFA have stopped this?

Act Before the Investigation Ends

The final numbers in the McKesson case may change. The questions for your own environment will not. Who can reset an account, and what do they need to prove? What can one SSO session open? Who can export large datasets? Would your SOC connect a new MFA device to a large export fast enough to stop it?

Strengthen Identity Security With Sennovate

Strengthen identity security with Sennovate. We help healthcare and enterprise teams secure SSO, harden account recovery, and monitor cloud access before a compromised identity turns into a data breach.