Aug 31
/
Latest News
McKesson Investigates Cyberattack as ShinyHunters Claims Theft of 284 Million Records
Healthcare giant McKesson is investigating a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming responsibility for stealing roughly 284 million records.
McKesson, one of the largest U.S. distributors of pharmaceuticals and medical supplies, said it detected the intrusion on August 25, 2026 and disclosed the incident in an SEC filing. The company said the investigation remains in its early stages and that it has not yet determined whether the breach is material or likely to affect operations or financial results.
In a notice to customers, Francisco Fraga, McKesson’s EVP and Chief Information and Technology Officer, confirmed that unauthorized access occurred within certain third-party applications tied to a subset of customers in the Oncology & Multispecialty and Medical-Surgical business units. He said McKesson’s security teams and external experts are working to limit operational impact, though customers may experience intermittent service degradation.
“Based on the information currently available, we do not believe any action is required by our customers and we are not proactively disconnecting systems within our environment at this time,” Fraga said, adding that McKesson continues to monitor its environment closely.
ShinyHunters told reporters it gained access through vishing calls to McKesson employees, using stolen credentials to compromise Okta single sign-on accounts. From there, the group claims it accessed Salesforce and Snowflake environments and exfiltrated about one terabyte of data over four days. The group says it demanded $55.2 million in ransom and alleges McKesson did not respond.
ShinyHunters claims to hold 284 million data records, including names, addresses, dates of birth, Social Security numbers, Medicaid details, medical record numbers, medication and allergy information, physician details, internal Salesforce records, and employee data. These claims have not been independently verified.
The incident adds to a growing wave of cyberattacks targeting healthcare and medtech companies this year, including recent breaches at Boston Scientific, Stryker, iRhythm Holdings, Novo Nordisk, and Xsolis.
McKesson, one of the largest U.S. distributors of pharmaceuticals and medical supplies, said it detected the intrusion on August 25, 2026 and disclosed the incident in an SEC filing. The company said the investigation remains in its early stages and that it has not yet determined whether the breach is material or likely to affect operations or financial results.
In a notice to customers, Francisco Fraga, McKesson’s EVP and Chief Information and Technology Officer, confirmed that unauthorized access occurred within certain third-party applications tied to a subset of customers in the Oncology & Multispecialty and Medical-Surgical business units. He said McKesson’s security teams and external experts are working to limit operational impact, though customers may experience intermittent service degradation.
“Based on the information currently available, we do not believe any action is required by our customers and we are not proactively disconnecting systems within our environment at this time,” Fraga said, adding that McKesson continues to monitor its environment closely.
ShinyHunters told reporters it gained access through vishing calls to McKesson employees, using stolen credentials to compromise Okta single sign-on accounts. From there, the group claims it accessed Salesforce and Snowflake environments and exfiltrated about one terabyte of data over four days. The group says it demanded $55.2 million in ransom and alleges McKesson did not respond.
ShinyHunters claims to hold 284 million data records, including names, addresses, dates of birth, Social Security numbers, Medicaid details, medical record numbers, medication and allergy information, physician details, internal Salesforce records, and employee data. These claims have not been independently verified.
The incident adds to a growing wave of cyberattacks targeting healthcare and medtech companies this year, including recent breaches at Boston Scientific, Stryker, iRhythm Holdings, Novo Nordisk, and Xsolis.
Executive IT Forums, Inc.
Educational Programs on Information Technology, Governance, Risk Management, & Compliance (GRC).
Our Newsletter
Get regular updates on CPE programs, news, and more.
Thank you!
Copyright © 2026 Executive IT Forums, Inc. All Rights Reserved.
Get started
Let us introduce our school
Write your awesome label here.