MCKESSON CYBERATTACK: SHINYHUNTERS CLAIMS 284 MILLION PATIENT RECORDS STOLEN

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and the theft of company data. The incident was discovered on August 25, 2026, and remains under investigation.

According to McKesson, the company activated its incident response procedures and brought in cybersecurity experts after discovering the breach. Some customers may also experience intermittent service disruptions connected to the incident. McKesson has not identified the affected third-party applications or publicly confirmed what types of information were compromised.

The ShinyHunters extortion group has claimed responsibility for the attack, alleging that hackers used voice phishing, or “vishing,” against McKesson employees to gain access. The group claims it obtained approximately 284 million patient records containing highly sensitive information, including names, addresses, Social Security numbers, medical record numbers, Medicaid information, prescriptions, medication details, and physician information.

ShinyHunters also reportedly demanded more than $55 million from McKesson after the alleged data theft. However, the hackers’ claims about the number and contents of the stolen records have not been independently verified, and McKesson has not confirmed them.

McKesson says its investigation is continuing and additional information will be released as the company determines the full scope and impact of the cybersecurity incident.

Leave a Comment

Your email address will not be published. Required fields are marked *