2026 McKesson — ShinyHunters extortion claim; company confirms third-party app intrusion (scope TBD)
Data compromised
Actor alleges patient PHI/PII, prescriptions, MRNs, SSNs, employee and physician records, and email content — unverified until McKesson census; company has not confirmed field list or 284M actor count
Technical writeup
Company-confirmed incident with unverified actor scale — August 28, 2026. ShinyHunters told CyberInsider it voice-phished two McKesson employees and exfiltrated data from Salesforce and Snowflake instances, demanding roughly $55.2M and claiming more than 284 million patient records including diagnoses, prescriptions, MRNs, SSNs, hospice/terminal-illness fields, and employee/physician directories. CyberInsider reviewed actor-provided samples consistent with healthcare CRM/warehouse content. After a request for comment, a McKesson spokesperson confirmed the company is in early stages of investigating a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data, with incident response and outside experts engaged; no public victim census or data-category list at indexing. recordsAffected 0 pending company/regulator count — the 284 million figure remains an unverified ShinyHunters marketing claim until McKesson or HHS OCR attests. companyConfirmed true for intrusion/exfiltration; actor count unverified.
Root cause
ShinyHunters claims vishing of employees then Salesforce/Snowflake exfiltration; McKesson confirms unauthorized access/exfiltration involving third-party applications and opened investigation (Aug 28, 2026)