McKesson discloses breach as ShinyHunters claims 284 million patient records
Healthcare and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, which the extortion group ShinyHunters claims exposed 284 million patient records. The group told reporters it broke in by voice-phishing two employees, then extracted data from the company's Salesforce and Snowflake environments, the same connected-app looting pattern it has used elsewhere. It claims deeply sensitive medical data was taken and says a roughly 55 million dollar ransom went unanswered. McKesson confirmed the incident in a regulatory filing but has not verified what was stolen, and the record count, like past ShinyHunters claims, may be inflated.
- Check
- Watch McKesson's official channels for confirmed details before acting on the 284 million figure, and if notified as affected, be alert to healthcare-themed phishing and identity theft using real medical details.
- Affected
- Patients and partners whose data McKesson handles, pending confirmation of scope; ShinyHunters claims names, Social Security numbers, and sensitive medical records were taken via phished access to Salesforce and Snowflake.
- Fix
- For organizations, harden connected SaaS like Salesforce and Snowflake against voice-phishing-led access with phishing-resistant authentication and tighter session controls, and verify large breach claims before treating headline numbers as confirmed.