**H1** McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft of 284 Million Records

**Introduction**

In a shocking revelation, healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. The ShinyHunters extortion group has claimed responsibility for stealing 284 million patient data records, sparking concerns about the security and privacy of sensitive healthcare information. As we delve into the details of this breach, it's essential to understand the significance of this incident and the measures that healthcare organizations must take to prevent similar attacks.

**The Incident**

According to McKesson's Form 8-K filing with the U.S. Securities and Exchange Commission (SEC), the company discovered the cybersecurity incident on August 25, 2026. The investigation remains in its early stages, and the company has not determined the material impact of the incident on its financial condition or operations. In a separate notice to customers, McKesson confirmed that the incident involved third-party applications and the unauthorized access and exfiltration of data. The company has warned customers that they may experience intermittent service degradation related to the attack.

**ShinyHunters' Claims**

The ShinyHunters extortion group has claimed responsibility for the attack, stating that they gained access after conducting voice phishing (vishing) social engineering attacks against multiple McKesson employees. The group claims that they compromised employees' Okta single sign-on accounts, which they used to access the company's Salesforce and Snowflake environments. The threat actor claims to have stolen a much larger collection of 284 million patient-related data records from Snowflake, including sensitive information such as names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, and email addresses.

**Technical Details**

ReliaQuest's Threat Research team recently documented a ShinyHunters campaign using domains that follow the company[.]claims pattern. These domains incorporate the targeted organization's name or abbreviation under the .claims TLD. ShinyHunters used the mckesson[.]claims domain as part of the attack, which matches a campaign recently documented by ReliaQuest. The threat actor claims to have exfiltrated about 1TB of data over four days, between August 21 and August 25.

**Implications and Concerns**

This breach highlights the growing concern of data-theft attacks targeting healthcare and health technology organizations. ShinyHunters has been linked to several recent attacks, including those targeting Medtronic, DentaQuest, iRhythm, OneMedical, and AdaptHealth. The attack comes amid an ongoing wave of data-theft attacks, with Health-ISAC warning healthcare organizations about increasing ShinyHunters attacks involving social engineering designed to compromise corporate accounts and gain access to cloud and SaaS platforms.

**Conclusion**

The McKesson breach serves as a stark reminder of the importance of robust cybersecurity measures in protecting sensitive healthcare information. As healthcare organizations continue to adopt cloud and SaaS platforms, they must prioritize the security of their systems and data. The ShinyHunters campaign highlights the effectiveness of social engineering attacks, emphasizing the need for organizations to educate their employees about the risks of vishing and other types of social engineering attacks. By understanding the tactics and techniques used by threat actors, organizations can take proactive measures to prevent similar attacks and protect the sensitive information of their patients.

**Recommendations**

* Healthcare organizations must prioritize the security of their systems and data, implementing robust cybersecurity measures to prevent unauthorized access. * Employees must be educated about the risks of social engineering attacks, including vishing and phishing. * Organizations must invest in incident response protocols, ensuring that they can quickly respond to and contain cyberattacks. * Collaboration between healthcare organizations and cybersecurity experts is essential in sharing threat intelligence and best practices for preventing data-theft attacks.

By staying vigilant and proactive, healthcare organizations can minimize the risk of data breaches and protect the sensitive information of their patients.