McKesson data breach: hackers claim 284 million records stolen, demand $55M

NewsTue, 01 Sep 2026 10:46:26 UTC2 hours ago
McKesson data breach: hackers claim 284 million records stolen, demand $55M

A pharmaceutical distribution giant just became the newest name on a growing list of American healthcare companies hit by hackers hunting for patient records. The McKesson data breach, disclosed on August 28, 2026, has already triggered a ransom demand worth tens of millions of dollars and put sensitive medical information for what could be millions of patients at risk.

Key takeaways

  • McKesson detected unauthorized access to third-party applications on August 25, 2026, and disclosed the incident in an SEC filing.
  • The extortion group ShinyHunters claims it stole roughly 284 million data records from McKesson’s Snowflake and Salesforce environments — a figure representing database rows, not confirmed unique patients.
  • Hackers say they used vishing calls to trick employees and hijack Okta single sign-on accounts, then moved laterally into cloud systems over a four-day window between August 21 and August 25.
  • ShinyHunters demanded a ransom of $55,236,150 and gave McKesson 72 hours to respond; the company reportedly never did.
  • McKesson confirmed intermittent service degradation but declined to say how many people were affected or what ransom demand it received.

The Breach and ShinyHunters’ Claims

McKesson’s own disclosure was carefully worded and short on detail, but it confirmed the core of the story: intruders got into third-party applications and pulled out data before the company caught on. The McKesson data breach was first flagged internally on August 25, 2026, and the company told the Securities and Exchange Commission its investigation was still “in its early stages,” adding it had not yet determined whether the incident was financially material.

… Continue reading the full article at the original source below.

Read from Source · en.cryptonomist.ch ↗
This content is automatically aggregated. Full credit goes to the original publisher (en.cryptonomist.ch).

Related