INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
ShinyHunters claims patient data theft from McKesson
| 2026-08-28 22:40 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
McKesson, a major U.S. healthcare company and pharmaceutical distributor, disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft on August 25, 2026, with the ShinyHunters extortion group claiming it stole 284 million patient data records. The attackers allegedly gained access through voice phishing or social engineering attacks against multiple McKesson employees, using a domain matching a previously documented ShinyHunters campaign to impersonate help desks and IT teams. This incident has affected approximately 284 million patients whose personal information was stolen from third-party applications used by McKesson. As of the date of the disclosure, McKesson's investigation remains in its early stages, with the company stating that it had not determined whether the incident is material or if it will have any impact on its financial condition or results of operations.
Technical Mitigations AI-generated
• Use a secure single sign-on (SSO) solution like Okta to protect against vishing attacks.
• Monitor for .claims domains and register your own domain with a similar pattern to prevent impersonation of help desks and IT teams.
• Regularly review Salesforce support cases for suspicious activity, especially after a known ShinyHunters campaign.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
ww•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
Global Scope
healthhealth
pharmaceuticalpharmaceutical
technologytechnology
Incident Timeline
August 25, 2026
ShinyHunters claimed to have stolen approximately 284 million patient-related data records from various healthcare organizations, including McKesson.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
The attack comes amid an ongoing wave of data-theft attacks targeting healthcare and health technology organizations attributed to ShinyHunters.
Health-ISAC
recently warned healthcare organizations
about increasing ShinyHunters attacks involving social engineering designed to compromise corporate accounts and gain access to cloud and SaaS platforms.
Other healthcare technology companies targeted in recent ShinyHunters data-theft attacks include
Medtronic
,
DentaQuest
,
iRhythm
, OneMedical, and AdaptHealth.
ShinyHunters declined to provide many technical details about the social engineering attacks, including the domain used during the campaign.
"ReliaQuest is tracking a widespread ShinyHunters campaign using domains that follow the company[.]claims pattern.
According to ShinyHunters, the threat actor exfiltrated about 1TB of data over four days, between August 21 and August 25.
ShinyHunters clarified to BleepingComputer that the figure is actually a raw count of approximately 284 million data records, or lines, rather than a count of unique individuals.
According to ShinyHunters, McKesson did not respond to or negotiate over the ransom demand.
data_breach
1 TB
According to ShinyHunters, the threat actor exfiltrated about 1TB of data over four days, between August 21 and August 25.
data_breach
284 patient data records
ShinyHunters clarified to BleepingComputer that the figure is actually a raw count of approximately 284 million data records, or lines, rather than a count of unique individuals.
The threat actor also claims the stolen Snowflake data contains approximately 284 million data records of patient-related information.
financial
$55,236,150 $ ransom
The group says it contacted McKesson after completing the data theft on August 25 and demanded a $55,236,150 ransom, giving the company 72 hours to respond.
2026/08/28
ShinyHunters claimed to have stolen 284 million patient data records from McKesson after conducting voice phishing, or vishing, social engineering attacks against multiple employees.
Click on any entity below to view its context and source!
threat_actor
ShinyHunters
…nd pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.
ShinyHunters claims responsibility
The ShinyHunters extortion group told BleepingComputer that it was behind the attack, claiming it gained access after conducting voice phishing, or vishing, social engineering attacks against multiple McKesson e…
This domain matches a ShinyHunters campaign recently documented by
ReliaQuest's Threat Research team
, which said the extortion group was registering .claims domains containing the names or abbreviations of targeted companies to impersonate their…
McKesson discloses breach after ShinyHunters claims patient data theft.
…rate the targeted organization's name or abbreviation under the .claims TLD," ReliaQuest said in a now-deleted post on X.
ShinyHunters told BleepingComputer that the vishing attacks led to the compromise of multiple employees' Okta single sign-on…
ShinyHunters claims the stolen information includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, dis…
data_breach
284 patient data records
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient da…
Tactical Metrics
Metrics
data_breach
284,000,000
Patient Data Records
Click for context!
Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient da…
ShinyHunters clarified to BleepingComputer that the figure is actually a raw count of approximately 284 million data records, or lines, rather than a count of unique individuals.
The threat actor also claims the stolen Snowflake data contains approximately 284 million data records of patient-related information.
Metrics
data_breach
1
Tb
According to ShinyHunters, the threat actor exfiltrated about 1TB of data over four days, between August 21 and August 25.
Metrics
financial
55,236,150
$ Ransom
The group says it contacted McKesson after completing the data theft on August 25 and demanded a $55,236,150 ransom, giving the company 72 hours to respond.
Intelligence Sources
BleepingComputer
2026-08-28
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-06T11:31
Comprehensive Tactical Telemetry
Highly Correlated Entities
18x
organisation
Identified Entity
Salesforce
entity
5x
tactic
Cyber Operation Type
Extortion
tactic
4x
industry
Targeted Sector
Healthcare
sector
4x
timeline
Temporal Reference
August 25, 2026
date
Contextual Telemetry
Context Block
8 METRICS
threat actor
APT Group
ShinyHunters
actor
data breach
Patient Data Records
284,000,000
patient data records
data breach
Tb
1
tb
financial
$ Ransom
55,236,150
$ ransom
general metric
Hours
72
hours
general metric
Blue Report
2,026
blue report
general metric
Simulations
338,000,000
simulations
general metric
Patients
284,000,000
patients
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.