TechNewsReel
Live

ShinyHunters Claims Breach of 284 Million McKesson Patient Records

The cybercrime group is demanding over $55 million after allegedly accessing Salesforce and Snowflake instances via voice-phishing.

TechNewsReel Newsroom · August 28, 2026

The threat actor group ShinyHunters has claimed responsibility for a massive data breach at McKesson, alleging the exposure of records belonging to 284 million patients. The claim marks one of the most significant targeted attacks on a global healthcare distributor to date.

According to reports from CyberInsider, ShinyHunters is demanding a ransom of $55,236,150 to resolve the incident. McKesson has officially confirmed to CyberInsider that it is currently investigating a cybersecurity incident involving the unauthorized access and exfiltration of data through third-party applications. The threat actors claim they gained entry by using voice-phishing techniques to deceive employees, which allowed them to compromise the company's Salesforce and Snowflake instances.

The Scale of the Attack

McKesson operates as a critical pillar of the global healthcare supply chain, serving as a major pharmaceutical distributor. Because of its central role in moving medications and managing healthcare data, the company is a high-value target for cybercriminals. ShinyHunters, the group behind the claim, is well-known in the security community for orchestrating several high-profile data thefts from large corporations, typically specializing in the exfiltration of massive datasets for ransom.

Industry Implications

If the claim of 284 million affected patients is verified, this would rank as one of the largest healthcare data leaks in history. Such a breach poses severe privacy risks to millions of individuals and exposes McKesson to potentially massive regulatory penalties under healthcare privacy laws. Furthermore, the alleged use of voice-phishing to breach enterprise-grade cloud environments like Snowflake and Salesforce highlights a persistent vulnerability: the human element. Despite sophisticated technical defenses, social engineering remains a primary vector for breaching critical infrastructure.

Ongoing Investigation

While McKesson has acknowledged the data exfiltration event, the full scope of the breach remains unconfirmed. The company's internal investigation is still ongoing to determine the exact number of affected patients and the specific nature of the stolen data. Security analysts are currently reviewing samples provided by the threat actors, but a full audit of the compromised systems is required to verify if the 284 million figure is accurate or an exaggeration intended to increase the pressure for ransom payment.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.