Skip to main content
VTechFusion Technologies
McKesson Confirms Breach After ShinyHunters Claims Theft of 284 Million Patient Records
InsightsNewsIndustry & AI News
Industry & AI News5 min readAugust 31, 2026

McKesson Confirms Breach After ShinyHunters Claims Theft of 284 Million Patient Records

VT

VTechFusion Team

VTechFusion Technologies

Healthcare giant McKesson confirmed a cybersecurity incident after the ShinyHunters extortion group claimed it stole 284 million records containing patient data. McKesson discovered the incident on August 25, 2026, with its investigation still in early stages.

How the Attack Unfolded

ShinyHunters told BleepingComputer that vishing (voice phishing) attacks compromised multiple McKesson employees' Okta single sign-on accounts, which the group then used to access the company's Salesforce and Snowflake environments — the same attack pattern seen across a wave of Salesforce/Snowflake-linked breaches this year. The group says it exfiltrated roughly 1TB of data over four days, between August 21 and August 25, 2026.

A $55 Million Ransom Demand

According to ShinyHunters, it contacted McKesson after finishing the theft on August 25 and demanded $55,236,150, giving the company a 72-hour deadline to respond.

What Data Was Reportedly Taken

  • Names, addresses, birth dates and Social Security numbers
  • Patient IDs, Medicaid details and medical record numbers
  • Medication and allergy information, plus physician information
  • Internal Salesforce records and employee data

An Important Clarification on the Headline Number

The widely cited "284 million" figure refers to rows of raw data, not unique patients — ShinyHunters itself has clarified that the 284 million records are linked to tens of millions of patients, with the exact number of affected individuals not yet confirmed. Reporting the raw record count as a patient count would meaningfully overstate the scope of the incident.

What This Means for Healthcare Data Security

This incident follows the same vishing-to-SSO-to-SaaS-platform pattern behind several other 2026 breaches, reinforcing that identity-layer social engineering — not a technical exploit of Salesforce or Snowflake themselves — remains the primary way attackers reach large stores of enterprise and patient data hosted in cloud SaaS platforms.

Filed under:Industry & AI News
All News

Frequently Asked Questions

What happened in the McKesson data breach?

McKesson confirmed a cybersecurity incident discovered on August 25, 2026, after ShinyHunters claimed it used vishing attacks to compromise employee Okta accounts and access McKesson's Salesforce and Snowflake environments, exfiltrating roughly 1TB of data over four days.

Does the 284 million figure mean 284 million patients were affected?

No. ShinyHunters has clarified that the 284 million figure refers to rows of raw data, not unique patients — the records are linked to tens of millions of patients, with the exact number of affected individuals not yet confirmed.

What ransom did ShinyHunters demand from McKesson?

ShinyHunters demanded $55,236,150, giving McKesson a 72-hour deadline to respond after completing the data theft on August 25, 2026.

Media & Press Enquiries

For editorial enquiries, expert commentary, or case study access.

Start Today

Ready to Build Something Great?

Let's turn your idea into a product. Book a free 30-minute discovery call with our team — no commitment, just clarity.