<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft-l9tbyabyk" -->

---
title: McKesson discloses breach after ShinyHunters claims...
description: McKesson, a major U.S. healthcare and pharmaceutical distributor, disclosed a cybersecurity incident discovered on August 25, 2026, involving unauthorized...
canonical: https://daily.dev/posts/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft-l9tbyabyk
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: McKesson discloses breach after ShinyHunters claims patient data theft | daily.dev
og:description: McKesson, a major U.S. healthcare and pharmaceutical distributor, disclosed a cybersecurity incident discovered on August 25, 2026, involving unauthorized...
og:url: https://daily.dev/posts/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft-l9tbyabyk
og:image: https://api.daily.dev/og/posts/l9tByaByk.png
og:image:alt: McKesson discloses breach after ShinyHunters claims patient data theft
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# McKesson discloses breach after ShinyHunters claims patient data theft

**[BleepingComputer](https://daily.dev/sources/bleepingcomputer)** · 5 min read · 0 upvotes · 0 comments

## Summary

McKesson, a major U.S. healthcare and pharmaceutical distributor, disclosed a cybersecurity incident discovered on August 25, 2026, involving unauthorized access to third-party applications and data exfiltration. The ShinyHunters extortion group claims responsibility, saying it used vishing attacks against employees to compromise Okta SSO accounts and then access McKesson's Salesforce and Snowflake environments, exfiltrating roughly 1TB of data over four days and about 284 million patient-related data records (not unique patients). The group claims stolen data includes SSNs, medical records, prescriptions, and demanded a $55,236,150 ransom, which McKesson did not pay. McKesson has not confirmed the scope or which applications were compromised, and the attack fits a broader ShinyHunters campaign targeting healthcare organizations like Medtronic, DentaQuest, and iRhythm.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft>

## Questions this post answers

### How did ShinyHunters gain access to McKesson's systems in the 2026 breach?

ShinyHunters claims it used voice phishing (vishing) social engineering attacks against multiple McKesson employees to compromise their Okta single sign-on accounts. With those compromised Okta credentials, the attackers then accessed McKesson's Salesforce and Snowflake environments, fully compromising Salesforce support cases and exfiltrating a larger set of patient data from Snowflake.

_Security teams tracking vishing and SSO-based breach techniques follow incident writeups like this on daily.dev._

### How many patients were affected by the McKesson data breach?

ShinyHunters claims to have stolen approximately 284 million data records from McKesson's Snowflake environment, but clarified this is a raw count of records or lines rather than a count of unique individuals. The group has not fully analyzed the data and does not know how many distinct people are represented, so the true number of impacted patients remains unknown.

_Anyone assessing breach scope and patient-data exposure claims can follow updates on daily.dev._

### What ransom did ShinyHunters demand from McKesson after the breach?

ShinyHunters demanded a ransom of $55,236,150 from McKesson after completing data theft on August 25, 2026, giving the company 72 hours to respond. According to the group, McKesson did not respond to or negotiate over the ransom demand, and the attackers exfiltrated roughly 1TB of data over four days leading up to the deadline.

_Those monitoring ransom demands and extortion tactics in healthcare breaches can track developments on daily.dev._

## Similar posts on daily.dev

- [Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare](https://daily.dev/posts/health-isac-warns-of-rising-shinyhunters-data-theft-attacks-on-healthcare-evur7xgel) · BleepingComputer · 0 upvotes · 0 comments
- [McGraw-Hill confirms data breach following extortion threat](https://daily.dev/posts/mcgraw-hill-confirms-data-breach-following-extortion-threat-khntotewy) · BleepingComputer · 0 upvotes · 0 comments
- [Data breach at edtech giant McGraw Hill affects 13.5 million accounts](https://daily.dev/posts/data-breach-at-edtech-giant-mcgraw-hill-affects-13-5-million-accounts-s5nmhalny) · BleepingComputer · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security), [#healthcare](https://daily.dev/tags/healthcare), [#data-breach](https://daily.dev/tags/data-breach), [#salesforce](https://daily.dev/tags/salesforce)

[View this post on daily.dev](https://daily.dev/posts/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft-l9tbyabyk)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"McKesson discloses breach after ShinyHunters claims patient data theft","url":"https://daily.dev/posts/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft-l9tbyabyk","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft-l9tbyabyk"},"datePublished":"2026-08-28T22:42:21.243Z","dateModified":"2026-08-31T19:02:01.986Z","description":"McKesson, a major U.S. healthcare and pharmaceutical distributor, disclosed a cybersecurity incident discovered on August 25, 2026, involving unauthorized...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/88e6ec68a9d4de16dade3584345f079a?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/88e6ec68a9d4de16dade3584345f079a?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"BleepingComputer","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"BleepingComputer","logo":"https://media.daily.dev/image/upload/s--as8nJ3qy--/f_auto,q_auto/v1774959951/logos/bleepingcomputer?_a=BAMAMiWQ0","url":"https://daily.dev/sources/bleepingcomputer"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft-l9tbyabyk","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"security,healthcare,data-breach,salesforce","timeRequired":"PT5M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"BleepingComputer","item":"https://daily.dev/sources/bleepingcomputer"},{"@type":"ListItem","position":3,"name":"McKesson discloses breach after ShinyHunters claims patient data theft"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft-l9tbyabyk#faq","mainEntity":[{"@type":"Question","name":"How did ShinyHunters gain access to McKesson's systems in the 2026 breach?","acceptedAnswer":{"@type":"Answer","text":"ShinyHunters claims it used voice phishing (vishing) social engineering attacks against multiple McKesson employees to compromise their Okta single sign-on accounts. With those compromised Okta credentials, the attackers then accessed McKesson's Salesforce and Snowflake environments, fully compromising Salesforce support cases and exfiltrating a larger set of patient data from Snowflake. Security teams tracking vishing and SSO-based breach techniques follow incident writeups like this on daily.dev."}},{"@type":"Question","name":"How many patients were affected by the McKesson data breach?","acceptedAnswer":{"@type":"Answer","text":"ShinyHunters claims to have stolen approximately 284 million data records from McKesson's Snowflake environment, but clarified this is a raw count of records or lines rather than a count of unique individuals. The group has not fully analyzed the data and does not know how many distinct people are represented, so the true number of impacted patients remains unknown. Anyone assessing breach scope and patient-data exposure claims can follow updates on daily.dev."}},{"@type":"Question","name":"What ransom did ShinyHunters demand from McKesson after the breach?","acceptedAnswer":{"@type":"Answer","text":"ShinyHunters demanded a ransom of $55,236,150 from McKesson after completing data theft on August 25, 2026, giving the company 72 hours to respond. According to the group, McKesson did not respond to or negotiate over the ransom demand, and the attackers exfiltrated roughly 1TB of data over four days leading up to the deadline. Those monitoring ransom demands and extortion tactics in healthcare breaches can track developments on daily.dev."}}]}
```

