INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters claims patient data theft at McKesson cybersecurity incident

| 2026-08-29 01:02 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
McKesson, a major U.S. healthcare company and pharmaceutical distributor, is investigating a cybersecurity incident involving unauthorized access to third-party applications and data theft by the ShinyHunters extortion group, which claims it stole 284 million patient data records. The breach occurred in early stages of investigation on August 28, with McKesson stating that no action was required by customers at this time. If technical issues arise, customers are advised to contact support channels. ShinyHunters issued a "Final Warning" to respond by September 1, but provided no proof for its claims. The incident is categorized as extortion and exfiltration of data, targeting the healthcare, pharmaceutical, technology sectors in the United States.
Technical Mitigations AI-generated
• Reset credentials and API keys that may have been exposed, and review access logs for the affected accounts or integrations.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
NORTH_AMERICA NORTH_AMERICA healthhealth pharmaceuticalpharmaceutical
Incident Timeline
‎2026/08/29
ShinyHunters claims to have stolen 284 million patient data records from McKesson, a pharmaceutical distribution giant.
threat_actor ShinyHunters
data_breach 284 patient data records
Tactical Metrics
Metrics
data_breach
284,000,000
Patient Data Records