TTO-2026-0830-001 · August 30, 2026 Data BreachHealthcare

ShinyHunters Claims 284 Million McKesson Patient Records via Vishing of Okta Accounts — $55.2 Million Ransom Demand Unanswered

mckesson.comShinyHunters284 million records claimed1TB exfiltratedOkta vishingSalesforce and Snowflake$55.2M ransom4 days August 21-25SEC 8-K filedSSNs diagnoses autopsy data

Summary

McKesson Corporation disclosed in a Form 8-K filing with the US Securities and Exchange Commission on August 28, 2026 that it discovered a cybersecurity incident on August 25 involving unauthorized access to third-party applications and exfiltration of data. The ShinyHunters extortion group claims responsibility, telling BleepingComputer it compromised multiple McKesson employees' Okta single sign-on accounts through vishing attacks, used those accounts to access McKesson's Salesforce and Snowflake environments, and exfiltrated approximately 1 terabyte of data over four days between August 21 and August 25. ShinyHunters claims the dataset contains approximately 284 million data records. The group clarified this figure represents a count of rows across tables, not a count of unique patients, since a single individual may appear across many records in healthcare data systems. The allegedly stolen data includes patient identifiers, SSNs, diagnoses, allergies, medications, disabilities, patient notes, appointment details, physician information, hospice and terminal illness information, causes of death, autopsy details, and doctor-patient communications. ShinyHunters demanded a ransom of $55,236,150 from McKesson, giving the company 72 hours to respond. McKesson did not respond and did not negotiate. ShinyHunters has not yet listed McKesson on its dark web leak site but has stated it will publish the data. McKesson stated that based on information currently available it does not believe any action is required by customers and is not proactively disconnecting systems. Health-ISAC recently warned healthcare organizations about increasing ShinyHunters attacks involving vishing designed to compromise Okta and other identity provider accounts for access to cloud and SaaS platforms.

Timeline

DateEvent
Aug 21, 2026ShinyHunters vishing attack compromises multiple McKesson employee Okta SSO accounts
Aug 21-25, 2026ShinyHunters accesses McKesson Salesforce and Snowflake environments — approximately 1TB exfiltrated over four days
Aug 25, 2026McKesson discovers cybersecurity incident — activates incident response protocols
Aug 25, 2026ShinyHunters contacts McKesson with $55,236,150 ransom demand — 72-hour response window
Aug 28, 2026McKesson does not respond to ransom demand — negotiation window expires
Aug 28, 2026McKesson files Form 8-K with SEC — discloses unauthorized access and data theft via third-party applications
Aug 30, 2026Investigation ongoing — ShinyHunters has not yet published data — patient count not confirmed by McKesson

Domain Intelligence

DomainScoreDKIMSPFDMARCStatus
mckesson.com61.38Live
WarmBadge Intelligence Snapshot · Captured: August 30, 2026 UTC

Context

mckesson.com scores 61.38 — a low-trust range score for one of the largest healthcare companies in the United States, with annual revenues exceeding $300 billion and a supply chain that reaches virtually every pharmacy, hospital, and clinic in the country. The score reflects accumulated signals in WarmBadge's live intelligence profile for the domain at the time of capture. The ShinyHunters attack chain against McKesson follows the same methodology the group used against Aura, ADT, RingCentral, ReliaQuest, and the series of healthcare technology companies targeted throughout 2026: a phone call to an employee impersonating a legitimate party, a credential surrender, an approved MFA push, and direct access to cloud and SaaS platforms that hold the organization's most sensitive data. No firewall was bypassed. No vulnerability was exploited. The attack required a phone, a convincing voice, and an employee who said yes. If the 284 million record claim and the data types described by ShinyHunters are accurate, this breach would represent one of the largest healthcare data exposures in US history, surpassing the Change Healthcare breach of 2024.

Domain intelligence available at warmbadge.com.
The Trust Observatory · thetrustobservatory.com · August 30, 2026