Summary
McKesson Corporation disclosed in a Form 8-K filing with the US Securities and Exchange Commission on August 28, 2026 that it discovered a cybersecurity incident on August 25 involving unauthorized access to third-party applications and exfiltration of data. The ShinyHunters extortion group claims responsibility, telling BleepingComputer it compromised multiple McKesson employees' Okta single sign-on accounts through vishing attacks, used those accounts to access McKesson's Salesforce and Snowflake environments, and exfiltrated approximately 1 terabyte of data over four days between August 21 and August 25. ShinyHunters claims the dataset contains approximately 284 million data records. The group clarified this figure represents a count of rows across tables, not a count of unique patients, since a single individual may appear across many records in healthcare data systems. The allegedly stolen data includes patient identifiers, SSNs, diagnoses, allergies, medications, disabilities, patient notes, appointment details, physician information, hospice and terminal illness information, causes of death, autopsy details, and doctor-patient communications. ShinyHunters demanded a ransom of $55,236,150 from McKesson, giving the company 72 hours to respond. McKesson did not respond and did not negotiate. ShinyHunters has not yet listed McKesson on its dark web leak site but has stated it will publish the data. McKesson stated that based on information currently available it does not believe any action is required by customers and is not proactively disconnecting systems. Health-ISAC recently warned healthcare organizations about increasing ShinyHunters attacks involving vishing designed to compromise Okta and other identity provider accounts for access to cloud and SaaS platforms.
Timeline
| Date | Event |
|---|---|
| Aug 21, 2026 | ShinyHunters vishing attack compromises multiple McKesson employee Okta SSO accounts |
| Aug 21-25, 2026 | ShinyHunters accesses McKesson Salesforce and Snowflake environments — approximately 1TB exfiltrated over four days |
| Aug 25, 2026 | McKesson discovers cybersecurity incident — activates incident response protocols |
| Aug 25, 2026 | ShinyHunters contacts McKesson with $55,236,150 ransom demand — 72-hour response window |
| Aug 28, 2026 | McKesson does not respond to ransom demand — negotiation window expires |
| Aug 28, 2026 | McKesson files Form 8-K with SEC — discloses unauthorized access and data theft via third-party applications |
| Aug 30, 2026 | Investigation ongoing — ShinyHunters has not yet published data — patient count not confirmed by McKesson |
Domain Intelligence
| Domain | Score | DKIM | SPF | DMARC | Status |
|---|---|---|---|---|---|
| mckesson.com | 61.38 | ✓ | ✓ | ✓ | Live |
Context
mckesson.com scores 61.38 — a low-trust range score for one of the largest healthcare companies in the United States, with annual revenues exceeding $300 billion and a supply chain that reaches virtually every pharmacy, hospital, and clinic in the country. The score reflects accumulated signals in WarmBadge's live intelligence profile for the domain at the time of capture. The ShinyHunters attack chain against McKesson follows the same methodology the group used against Aura, ADT, RingCentral, ReliaQuest, and the series of healthcare technology companies targeted throughout 2026: a phone call to an employee impersonating a legitimate party, a credential surrender, an approved MFA push, and direct access to cloud and SaaS platforms that hold the organization's most sensitive data. No firewall was bypassed. No vulnerability was exploited. The attack required a phone, a convincing voice, and an employee who said yes. If the 284 million record claim and the data types described by ShinyHunters are accurate, this breach would represent one of the largest healthcare data exposures in US history, surpassing the Change Healthcare breach of 2024.
The Trust Observatory · thetrustobservatory.com · August 30, 2026