US healthcare giant McKesson breached, ShinyHunters claims 284m patient records
ShinyHunters said it had contacted McKesson and made a $55,236,150 ransom demand.

Via Shutterstock
- McKesson confirmed unauthorized access to third-party applications and data theft after discovering the incident on August 25th.
- ShinyHunters claims it stole about 284 million records, but that may not mean unique patients.
- The allegedly stolen data includes patient identifiers, medical details, billing information, and doctor-patient messages.
- McKesson says its investigation is early and it currently does not believe customers need to act.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Major US healthcare company McKesson confirmed a cyberattack after ShinyHunters claimed to have stolen more than 284 million records containing patient data.
On August 25th, McKesson discovered a cybersecurity incident affecting its information systems, the company said in its Form 8-K filing with the US Securities and Exchange Commission.
McKesson said that at the time of the filing, it had not determined that the incident is material or that it’s likely to have any material impact on the company, including its financial condition or results of operations.
In a note to customers, McKesson said the incident involved unauthorized access to third-party applications and data exfiltration.
“We take the security and privacy of our partners, customers and their patients very seriously. Upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to assist in our response,” the company said.
Based on currently available information, McKesson said it does not believe customers need to take any action and it is not actively disconnecting systems.
The investigation is currently in its early stages.
McKesson has not disclosed which third-party applications were involved or how the attackers gained access.
ShinyHunters claims responsibility
ShinyHunters, a cybercriminal and data extortion group, claimed responsibility for the attack and provided data samples to CyberInsider for review. CyberInsider said that the samples appeared consistent with the types of information described in the claims.
The group claims the stolen data relates to tens of millions of patients and contains roughly 284 million records, although the exact number of affected individuals remains unclear.
ShinyHunters said the compromised information includes names, addresses, Social Security numbers, medical records, diagnoses, medications, billing information, and highly sensitive details such as terminal illnesses, causes of death, and sexual orientation.
Employee, physician, and clinic data, as well as doctor-patient communications, were also allegedly stolen.
While McKesson has not disclosed how the attack occurred, ShinyHunters told BleepingComputer that it targeted multiple McKesson employees with voice phishing, allegedly using the mckesson[.]claims domain.
ShinyHunters said the vishing attacks allowed it to compromise multiple employees’ Okta single sign-on accounts, which it used to access McKesson’s Salesforce and Snowflake environments.
The group then managed to fully compromise the Salesforce environment, including support cases, and exfiltrated about 1TB of data over four days, between August 21st and August 25th, it said.
The threat actor clarified to BleepingComputer that the 284 million figure refers to a rough estimate of data records, not unique individuals. It added that it has not yet fully analyzed the data.
ShinyHunters said that it had contacted McKesson and made a $55,236,150 ransom demand, giving the company 72 hours to respond. The group said it had not received a response and that McKesson had not attempted to negotiate.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
McKesson Corporation is one of the largest distributors of prescription drugs, medical supplies, and health information technology in the US, ranking near the top of the Fortune 500 list.
Earlier in August, ShinyHunters claimed it stole 12.9 million CyrusOne Salesforce records and said it made a $13 million extortion demand.