← All articles

McKesson discloses breach as ShinyHunters claims 284 million patient records

Healthcare and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, which the extortion group ShinyHunters claims exposed 284 million patient records. The group told reporters it broke in by voice-phishing two employees, then extracted data from the company's Salesforce and Snowflake environments, the same connected-app looting pattern it has used elsewhere. It claims deeply sensitive medical data was taken and says a roughly 55 million dollar ransom went unanswered. McKesson confirmed the incident in a regulatory filing but has not verified what was stolen, and the record count, like past ShinyHunters claims, may be inflated.

Check
Watch McKesson's official channels for confirmed details before acting on the 284 million figure, and if notified as affected, be alert to healthcare-themed phishing and identity theft using real medical details.
Affected
Patients and partners whose data McKesson handles, pending confirmation of scope; ShinyHunters claims names, Social Security numbers, and sensitive medical records were taken via phished access to Salesforce and Snowflake.
Fix
For organizations, harden connected SaaS like Salesforce and Snowflake against voice-phishing-led access with phishing-resistant authentication and tighter session controls, and verify large breach claims before treating headline numbers as confirmed.