
VTechFusion Team
VTechFusion Technologies
Healthcare giant McKesson confirmed a cybersecurity incident after the ShinyHunters extortion group claimed it stole 284 million records containing patient data. McKesson discovered the incident on August 25, 2026, with its investigation still in early stages.
How the Attack Unfolded
ShinyHunters told BleepingComputer that vishing (voice phishing) attacks compromised multiple McKesson employees' Okta single sign-on accounts, which the group then used to access the company's Salesforce and Snowflake environments — the same attack pattern seen across a wave of Salesforce/Snowflake-linked breaches this year. The group says it exfiltrated roughly 1TB of data over four days, between August 21 and August 25, 2026.
A $55 Million Ransom Demand
According to ShinyHunters, it contacted McKesson after finishing the theft on August 25 and demanded $55,236,150, giving the company a 72-hour deadline to respond.
What Data Was Reportedly Taken
- Names, addresses, birth dates and Social Security numbers
- Patient IDs, Medicaid details and medical record numbers
- Medication and allergy information, plus physician information
- Internal Salesforce records and employee data
An Important Clarification on the Headline Number
The widely cited "284 million" figure refers to rows of raw data, not unique patients — ShinyHunters itself has clarified that the 284 million records are linked to tens of millions of patients, with the exact number of affected individuals not yet confirmed. Reporting the raw record count as a patient count would meaningfully overstate the scope of the incident.
What This Means for Healthcare Data Security
This incident follows the same vishing-to-SSO-to-SaaS-platform pattern behind several other 2026 breaches, reinforcing that identity-layer social engineering — not a technical exploit of Salesforce or Snowflake themselves — remains the primary way attackers reach large stores of enterprise and patient data hosted in cloud SaaS platforms.
Frequently Asked Questions
What happened in the McKesson data breach?
McKesson confirmed a cybersecurity incident discovered on August 25, 2026, after ShinyHunters claimed it used vishing attacks to compromise employee Okta accounts and access McKesson's Salesforce and Snowflake environments, exfiltrating roughly 1TB of data over four days.
Does the 284 million figure mean 284 million patients were affected?
No. ShinyHunters has clarified that the 284 million figure refers to rows of raw data, not unique patients — the records are linked to tens of millions of patients, with the exact number of affected individuals not yet confirmed.
What ransom did ShinyHunters demand from McKesson?
ShinyHunters demanded $55,236,150, giving McKesson a 72-hour deadline to respond after completing the data theft on August 25, 2026.
Media & Press Enquiries
For editorial enquiries, expert commentary, or case study access.
Ready to Build Something Great?
Let's turn your idea into a product. Book a free 30-minute discovery call with our team — no commitment, just clarity.
