ShinyHunters stated it accessed McKesson's network by using phishing and social engineering to trick employees into granting access. The group claimed it stole millions of rows of patient data from McKesson's cloud-hosted Snowflake and Salesforce environments. According to BleepingComputer, the ShinyHunters group claims the 284 million figure represents a raw count of data records from the Snowflake environment rather than unique individuals.
The stolen data includes personally identifiable information such as names, addresses, and Social Security numbers, ShinyHunters stated. The group also said the data includes protected health information such as diagnoses, medications, allergies, and patient notes. Additionally, ShinyHunters stated the compromised information includes prescription and billing records, employee records, and information about McKesson’s customer physicians and clinics. The group noted that the stolen data includes McKesson employees' home addresses.
TechCrunch verified a small subset of the data shared by ShinyHunters against public records. The hacking group added McKesson to its Tor-based leak site following the theft. CyberScoop reported that the ShinyHunters extortion group set a deadline of September 1, 2026, for McKesson to respond to its ransom demand. The amount of the ransom was not independently verified.
McKesson Chief Technology Officer Francisco Fraga stated in a notice to customers that the stolen data relates to the company's Oncology & Multispecialty and Medical-Surgical business units. Help Net Security reported that McKesson stated the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within those business units. McKesson stated it believes there is no ongoing unauthorized activity in its systems and that it was not disconnecting any systems in response to the incident.
McKesson stated it expected intermittent service degradation related to the incident. The company also stated it would provide complimentary credit monitoring and identity protection services to impacted individuals. McKesson spokesperson Kristina Chang stated the company continues to operate in all lines of business. McKesson delivers roughly one-third of prescription medicines to North American hospitals, pharmacies, and healthcare clinics and operates the Health Mart pharmacy franchise.
Timeline
The largest healthcare data breach happened in 2024, involving a cyberattack on Change Healthcare, which compromised the personal and medical data of around 192.7 million people. Reported data breaches reached a record high in 2025, with nearly 800 reported to the U.S. Department of Health and Human Services. McKesson stated in a filing with the U.S. Securities and Exchange Commission that it discovered a cybersecurity incident affecting its information systems on August 25, 2026. McKesson confirmed on August 29, 2026, that hackers exfiltrated data from its information systems.
What's New
Research titled "What are ShinyHunters, the hackers that attacked Google? Should we all be worried?" was published in 2025. The ShinyHunters group claims it stole approximately 284 million data records from McKesson's Snowflake environment, which represents a raw count of data records rather than unique individuals. ShinyHunters claimed to have stolen 284 million customer records from McKesson.
The ShinyHunters hacking group has previously claimed responsibility for data breaches at Amazon-owned One Medical and dental insurance company DentaQuest following cyberattacks on their systems. ShinyHunters threatened to make the stolen information public unless McKesson contacted them to start payment negotiations by September 1, 2026. Data from the U.S. Department of Health and Human Services Office for Civil Rights shows that health data breaches affect, on average, 59 million people each year. ShinyHunters stated the compromised information includes prescription and billing records, employee records, and information about McKesson’s customer physicians and clinics.
Why It Matters
The Get the Facts Data Team analyzed over 7,800 data breaches reported to the U.S. Department of Health and Human Services and found that on average, a reported health data breach affects 136,300 individuals. The ShinyHunters hacking group has previously claimed responsibility for data breaches at Amazon-owned One Medical and dental insurance company DentaQuest. Medical device maker Boston Scientific was hit by a cyberattack last week that knocked much of the company’s network offline, and health tech company TriZetto had a breach affecting over 3 million patients.
forum Comments (0)
No comments yet. Be the first to comment.