Aug 30, 2026 · 7 min read
ShinyHunters Claim 284M McKesson Patient Records
McKesson has confirmed an intrusion and confirmed data was taken. It has not confirmed the number everybody is quoting, and the group that supplied that number has already qualified it.
McKesson moves more prescription medicine than any company in North America, on $403.4 billion of revenue in the year to March 2026 per its fiscal 2026 results announcement. On August 28 it disclosed that someone had been inside its third party applications and had taken data out. The extortion crew ShinyHunters says that data amounted to 284 million patient records. McKesson has confirmed no such figure, and the number is doing more work in headlines than the people who supplied it can support.
Key Takeaways
- McKesson discovered the incident on August 25, 2026 and disclosed it on August 28, confirming unauthorized access to third party applications and data exfiltration while calling the investigation early stage.
- ShinyHunters claims 284 million records; McKesson has not confirmed that figure, and the group itself says the number counts database rows, not people.
- The claimed route was voice phishing against McKesson staff, then compromised Okta single sign on accounts, then Salesforce and Snowflake, a chain CISA and the FBI documented in November 2023.
- ShinyHunters says it took roughly 1TB between August 21 and 25 and demanded $55,236,150 inside a 72 hour deadline McKesson never answered.
- The claimed dataset ties email addresses to prescriptions, diagnoses and named physicians: raw material for healthcare themed phishing rather than generic spam.
What Did McKesson Actually Confirm?
Three things, and none of them is a number. McKesson confirmed unauthorized access to third party applications, confirmed that data was exfiltrated, and said the investigation remains in its early stages.
The company's statement, reported by BleepingComputer, says it "immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts." It also warned customers of possible service degradation and told the SEC it has not judged the incident material, an assessment that can change.
Read the gaps rather than the words. McKesson has not named the applications, described the intrusion route, listed the data categories, or endorsed the 284 million figure. Every specific detail in circulation comes from the people demanding the money.
Is the 284 Million Figure Real?
It is unverified, and the group that produced it has said it does not mean what the headlines imply. ShinyHunters told CyberInsider that "284 million records were obtained, linked to tens of millions of patients, but the exact number of people in the breach is not yet known."
That distinction collapses the most viral version of this story. The US Census Bureau puts the national population near 342 million, so 284 million people would be five of every six Americans. A drug distributor's Snowflake warehouse holds rows, not patients: one per prescription, per shipment, per invoice. A patient on three long term medications generates dozens a year.
Here is the comparison that actually sets the scale. Across the whole first half of 2026, the HHS Office for Civil Rights breach portal logged 189 large healthcare breaches affecting a combined 19 million individuals, the biggest being TriZetto Provider Solutions at 3.43 million. If even ShinyHunters' cautious "tens of millions" holds, McKesson alone would exceed every other US healthcare breach of 2026 combined, several times over. The claim does not need to be 284 million to be the year's worst.
How Did the Attackers Get In?
By telephone, according to ShinyHunters. The group says voice phishing calls against several McKesson employees yielded working Okta single sign on credentials, and those accounts opened the door to the company's Salesforce and Snowflake environments.
Notice what is missing. No exploit, no CVE, no malware, no ransomware. The attackers never needed McKesson's network because the data was not on it, and Salesforce and Snowflake answer to anyone holding a valid session.
Google's threat intelligence team profiled this playbook in June 2025 as UNC6040, in a write up titled The Cost of a Call: From Voice Phishing to Data Extortion. It describes operators impersonating IT support, walking victims through Okta phishing panels, and extorting them later with a 72 hour bitcoin deadline under the ShinyHunters name. The McKesson demand carried a 72 hour deadline. That is not coincidence; it is a script being rerun.
Why Has the Same Phone Call Worked All Year?
Because nothing about it has needed to improve. Track the intrusions we have covered through 2026: the initial access step is identical every time, while the haul climbs steadily.
- May 2026: Cushman & Wakefield lost 50GB of Salesforce data after a phone call, and the files went public when the deadline passed.
- May 2026: Charter Communications gave up 40 million customer records through a single vished Microsoft Entra account.
- July 2026: Brinks Home was breached by voice phishing, a home security company undone by the oldest trick on the list.
- August 2026: RingCentral, 1.6 million accounts, then Baxter, 7.1 million Salesforce records, then Carhartt, 12.9 million customer accounts, all inside four weeks.
Six victims, one method, and a jump from 50GB to a claimed terabyte. The CISA and FBI advisory describing help desk impersonation and one time password harvesting landed in November 2023, and nearly three years on the same steps still work against a Fortune 10 company. Nobody here is being outsmarted; they are being out dialled.
The damage grows while the technique stands still because the target moved. Companies hardened the network perimeter for a decade, then put their most sensitive records in Salesforce and Snowflake, where the only perimeter left is an employee's willingness to believe a caller. Phishing resistant multifactor authentication, the FIDO and WebAuthn hardware key kind rather than codes read aloud, would have broken every intrusion above. Most of these companies had multifactor authentication. It was the wrong kind.
What This Means for Your Inbox
A retail breach leaks an email address and a purchase. This one, if the claimed contents hold, leaks an email address attached to your medication list, your diagnosis and the doctor who treats you. That combination is the difference between spam and a message you have no reason to doubt.
Consider what a scam email can say when the sender knows the answers. Not "your pharmacy account needs attention" but a note naming your real prescription, physician and clinic, asking you to confirm insurance details before your next refill. Nothing about it fails the tests people are taught to apply. Healthcare records are also uniquely coercive because they cannot be reissued. A bank sends a new card; a diagnosis is permanent leverage.
This follow on wave is predictable because we have watched it happen. After earlier ShinyHunters dumps, leaked addresses fed straight into a sextortion campaign demanding around $2,000 per victim, the leaked detail included purely to prove the sender held real data. Expect the healthcare flavoured version within weeks, whether or not McKesson ever confirms a number.
What Should You Do Right Now?
Assume the data exists, because waiting for a notification letter costs months. McKesson sits between manufacturers and pharmacies, so you may sit in its systems without ever having heard of it.
- Check your addresses on Have I Been Pwned. Nothing from this incident is indexed yet, so register for notifications rather than checking once.
- Freeze your credit at all three bureaus. Social Security numbers are among the claimed fields, and the FTC's guidance on credit freezes covers a process that is free and reversible.
- Treat every pharmacy or prescription message as unverified, especially accurate ones. Accuracy is now evidence of a leak, not of legitimacy. Never confirm details a caller or email recites to you; reach your pharmacy through a number or app you already had.
- Read your explanation of benefits statements. Medical identity theft surfaces as treatment you never received, and that paperwork is usually where it shows first.
What to Watch Next
One document will settle what the headlines cannot: a filing on the HHS breach portal, where the HIPAA breach notification rule forces a covered entity or business associate to report a count of affected individuals. That number will be McKesson's, checked against its own records, and it is the only figure worth anchoring to. The gap between a claim and a filing can run long: Aesto Health took 246 days to move from intrusion to notification letters for 9.5 million patients, and it is a business associate of the same kind.
Watch the leak site too, because ShinyHunters says McKesson never negotiated and the Cushman & Wakefield case showed what follows a passed deadline. Publication is the point at which 284 million becomes either a fact or a marketing number. Until then it belongs in quotation marks, and coverage stating it flatly has skipped a step the attackers themselves did not.