Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Google further buries search results under AI mode

    August 29, 2026

    McKesson discloses breach after ShinyHunters claims patient data theft

    August 28, 2026

    Chelsea FC Gets a Stablecoin Sponsor after UK FCA Warning to Clubs

    August 28, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Google further buries search results under AI mode
    • McKesson discloses breach after ShinyHunters claims patient data theft
    • Chelsea FC Gets a Stablecoin Sponsor after UK FCA Warning to Clubs
    • President Trump Signs Executive Order to Create US Space Academy  
    • Trump Administration Speeds Up Environmental Review for 800-Mile Alaska Oil Pipeline
    • Why Are Yields on U.S. Treasury Bonds Rising?
    • What We Know About Pennsylvania’s Two ‘Measles-Associated’ Deaths
    • Man, 41, dies after large sign falls at Christian festival in West Sussex | West Sussex
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Saturday, August 29
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    McKesson discloses breach after ShinyHunters claims patient data theft

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 28, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.

    McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies.

    CyberInsider first reported the breach earlier today, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission.

    image

    McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation remains in the early stages.

    “Information about the incident, including any updates, is available on the company’s website at www.mckesson.com/cybersecurity,” McKesson said in its SEC filing.

    “As of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations.”

    In a separate notice to customers, McKesson confirmed that the incident involved third-party applications and the unauthorized access and exfiltration of data.

    “We take the security and privacy of our partners, customers and their patients very seriously. Upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to assist in our response,” reads McKesson’s notice.

    The company said its investigation is ongoing to determine the full scope of the incident.

    McKesson also warned that customers may experience intermittent service degradation believed to be related to the attack, although the company said it was not proactively disconnecting systems within its environment.

    At this time, McKesson has not publicly disclosed which third-party applications were compromised, how the attackers gained access, or what information was stolen.

    McKesson says its investigation remains ongoing and that it will provide additional information as it develops a more complete understanding of the incident.

    ShinyHunters claims responsibility

    The ShinyHunters extortion group told BleepingComputer that it was behind the attack, claiming it gained access after conducting voice phishing, or vishing, social engineering attacks against multiple McKesson employees.

    ShinyHunters declined to provide many technical details about the social engineering attacks, including the domain used during the campaign. However, BleepingComputer learned from another source that the threat actors used the mckesson[.]claims domain as part of the attack.

    This domain matches a ShinyHunters campaign recently documented by ReliaQuest’s Threat Research team, which said the extortion group was registering .claims domains containing the names or abbreviations of targeted companies to impersonate their help desks and IT teams.

    “ReliaQuest is tracking a widespread ShinyHunters campaign using domains that follow the company[.]claims pattern. These domains incorporate the targeted organization’s name or abbreviation under the .claims TLD,” ReliaQuest said in a now-deleted post on X.

    ShinyHunters told BleepingComputer that the vishing attacks led to the compromise of multiple employees’ Okta single sign-on accounts, which they then used to access the company’s Salesforce and Snowflake environments.

    The threat actor claims it fully compromised the Salesforce environment, including support cases. The threat actor also allegedly stole a much larger collection of patient-related data from Snowflake.

    According to ShinyHunters, the threat actor exfiltrated about 1TB of data over four days, between August 21 and August 25.

    The threat actor also claims the stolen Snowflake data contains approximately 284 million data records of patient-related information. However, this does not mean that the breach impacted 284 million patients.

    Previous reporting stated that information belonging to 284 million patients had been exposed. ShinyHunters clarified to BleepingComputer that the figure is actually a raw count of approximately 284 million data records, or lines, rather than a count of unique individuals.

    The threat actor told BleepingComputer that it has not fully analyzed the stolen data and does not know how many unique people are in those records.

    ShinyHunters claims the stolen information includes names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information, and physician information.

    The group also claims the data contains information related to deceased and terminally ill patients, prescriptions and medication shipments, invoices, employee information, Salesforce records, internal communications, and healthcare providers and clinics using McKesson’s services.

    BleepingComputer has not independently verified these claims, and McKesson has not publicly disclosed what information was stolen.

    The group says it contacted McKesson after completing the data theft on August 25 and demanded a $55,236,150 ransom, giving the company 72 hours to respond. According to ShinyHunters, McKesson did not respond to or negotiate over the ransom demand.

    The attack comes amid an ongoing wave of data-theft attacks targeting healthcare and health technology organizations attributed to ShinyHunters.

    Health-ISAC recently warned healthcare organizations about increasing ShinyHunters attacks involving social engineering designed to compromise corporate accounts and gain access to cloud and SaaS platforms.

    Other healthcare technology companies targeted in recent ShinyHunters data-theft attacks include Medtronic, DentaQuest, iRhythm, OneMedical, and AdaptHealth.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    breach claims data discloses McKesson patient ShinyHunters theft
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Offensive Security Investments Surge as AI Threats Increase

    Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers

    Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable

    In Other News: Log4j RCE Scare, Minimus Shutdown, Iranian Hacker Sanctions

    Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

    Over 8,300 Gitea servers vulnerable to code execution attacks

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Google further buries search results under AI mode

    August 29, 2026

    McKesson discloses breach after ShinyHunters claims patient data theft

    August 28, 2026

    Chelsea FC Gets a Stablecoin Sponsor after UK FCA Warning to Clubs

    August 28, 2026

    President Trump Signs Executive Order to Create US Space Academy  

    August 28, 2026
    Latest Posts

    NASA Awards 2026 Innovative Technology Concepts

    July 30, 2026

    Microsoft Quietly Adds New Windows App That Wants to Scan Your Face

    July 30, 2026

    US Bans Foreign-Made Humanoid Robots, Targeting China Over National Security

    July 30, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Google further buries search results under AI mode

    August 29, 2026

    McKesson discloses breach after ShinyHunters claims patient data theft

    August 28, 2026

    Chelsea FC Gets a Stablecoin Sponsor after UK FCA Warning to Clubs

    August 28, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.