McKesson Corporation and Salesforce: ShinyHunters claims McKesson data breach exposing 284 million patients

McKesson Corporation and Salesforce: ShinyHunters claims McKesson data breach exposing 284 million patients

McKesson Hit by Massive Data Breach: ShinyHunters Claims Theft of 284M Patient Records

The ShinyHunters threat group has claimed responsibility for a major cyberattack on McKesson Corporation, one of the largest U.S. healthcare distributors, alleging the theft of 284 million patient records containing highly sensitive medical, identity, and prescription data. CyberInsider reviewed samples provided by the threat actor, which appear consistent with the breach claims.

McKesson confirmed the incident in a statement, revealing that an investigation is underway into unauthorized access and data exfiltration via third-party applications. The company activated its incident response protocols, engaged cybersecurity experts, and is working to assess the scope and impact. No further details on the breach’s origin or timeline have been disclosed.

According to ShinyHunters, the stolen data includes:

  • Patient records: Full names, addresses, Social Security numbers, medical histories (diagnoses, allergies, medications), hospice and terminal illness details, sexual orientation, and predictive health assessments (e.g., cancer risk).
  • Prescription and billing data: Medication orders, invoices, shipment details, and tracking numbers.
  • Healthcare provider information: Physician names, practice locations, clinic details, and employee records (including job roles and contact data).
  • Communications: Email content between doctors and patients (excluding attachments).

The threat actors claim they gained access by voice-phishing two McKesson employees before extracting data from Salesforce and Snowflake instances. ShinyHunters is demanding a $55.2 million ransom to prevent the release of the stolen files but stated that McKesson has not responded to their demands.

The breach exposes patients and providers to heightened risks of identity theft, medical fraud, and targeted phishing attacks. McKesson’s investigation remains ongoing, with updates expected as more details emerge.

Source: https://cyberinsider.com/mckesson-data-breach-exposing-284-million-patients/

McKesson Corporation TPRM report: https://www.rankiteo.com/company/mckesson

Salesforce TPRM report: https://www.rankiteo.com/company/salesforce

"id": "salmck1787948754",
"linkid": "salesforce, mckesson",
"type": "Breach",
"date": "8/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': '284 million patients and '
                                              'healthcare providers',
                        'industry': 'Healthcare',
                        'location': 'U.S.',
                        'name': 'McKesson Corporation',
                        'size': 'Large',
                        'type': 'Healthcare Distributor'}],
 'attack_vector': 'Voice-phishing (vishing)',
 'data_breach': {'data_exfiltration': 'Yes',
                 'number_of_records_exposed': '284 million',
                 'personally_identifiable_information': 'Yes',
                 'sensitivity_of_data': 'High',
                 'type_of_data_compromised': ['Patient records (full names, '
                                              'addresses, Social Security '
                                              'numbers, medical histories, '
                                              'diagnoses, allergies, '
                                              'medications)',
                                              'Hospice and terminal illness '
                                              'details',
                                              'Sexual orientation',
                                              'Predictive health assessments '
                                              '(e.g., cancer risk)',
                                              'Prescription and billing data '
                                              '(medication orders, invoices, '
                                              'shipment details, tracking '
                                              'numbers)',
                                              'Healthcare provider information '
                                              '(physician names, practice '
                                              'locations, clinic details, '
                                              'employee records)',
                                              'Email communications between '
                                              'doctors and patients']},
 'description': 'The ShinyHunters threat group has claimed responsibility for '
                'a major cyberattack on McKesson Corporation, alleging the '
                'theft of 284 million patient records containing highly '
                'sensitive medical, identity, and prescription data. The '
                'breach exposes patients and providers to heightened risks of '
                'identity theft, medical fraud, and targeted phishing attacks. '
                'McKesson confirmed unauthorized access and data exfiltration '
                'via third-party applications and is investigating the '
                'incident.',
 'impact': {'brand_reputation_impact': 'High',
            'data_compromised': '284 million patient records',
            'identity_theft_risk': 'High',
            'legal_liabilities': 'Potential',
            'systems_affected': ['Salesforce', 'Snowflake']},
 'initial_access_broker': {'entry_point': 'Voice-phishing two McKesson '
                                          'employees'},
 'investigation_status': 'Ongoing',
 'motivation': 'Financial gain (ransom demand)',
 'ransomware': {'data_exfiltration': 'Yes',
                'ransom_demanded': '$55.2 million',
                'ransom_paid': 'No response from McKesson'},
 'references': [{'source': 'CyberInsider'}],
 'regulatory_compliance': {'regulations_violated': ['Potential HIPAA '
                                                    'violations']},
 'response': {'communication_strategy': 'Public statement issued',
              'incident_response_plan_activated': 'Yes',
              'third_party_assistance': 'Cybersecurity experts'},
 'threat_actor': 'ShinyHunters',
 'title': 'McKesson Hit by Massive Data Breach: ShinyHunters Claims Theft of '
          '284M Patient Records',
 'type': 'Data Breach',
 'vulnerability_exploited': 'Third-party applications (Salesforce and '
                            'Snowflake instances)'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.