INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

ShinyHunters claims patient data theft from McKesson

| 2026-08-28 22:40 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
McKesson, a major U.S. healthcare company and pharmaceutical distributor, disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft on August 25, 2026, with the ShinyHunters extortion group claiming it stole 284 million patient data records. The attackers allegedly gained access through voice phishing or social engineering attacks against multiple McKesson employees, using a domain matching a previously documented ShinyHunters campaign to impersonate help desks and IT teams. This incident has affected approximately 284 million patients whose personal information was stolen from third-party applications used by McKesson. As of the date of the disclosure, McKesson's investigation remains in its early stages, with the company stating that it had not determined whether the incident is material or if it will have any impact on its financial condition or results of operations.
Technical Mitigations AI-generated
• Use a secure single sign-on (SSO) solution like Okta to protect against vishing attacks. • Monitor for .claims domains and register your own domain with a similar pattern to prevent impersonation of help desks and IT teams. • Regularly review Salesforce support cases for suspicious activity, especially after a known ShinyHunters campaign.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

ww•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters
Target & Sectors
Global Scope healthhealth pharmaceuticalpharmaceutical technologytechnology
Incident Timeline
‎August 25, 2026
ShinyHunters claimed to have stolen approximately 284 million patient-related data records from various healthcare organizations, including McKesson.
threat_actor ShinyHunters
data_breach 1 TB
data_breach 284 patient data records
financial $55,236,150 $ ransom
‎2026/08/28
ShinyHunters claimed to have stolen 284 million patient data records from McKesson after conducting voice phishing, or vishing, social engineering attacks against multiple employees.
threat_actor ShinyHunters
data_breach 284 patient data records
Tactical Metrics
Metrics
data_breach
284,000,000
Patient Data Records
Metrics
data_breach
1
Tb
Metrics
financial
55,236,150
$ Ransom
Intelligence Sources