A data breach at McKesson has spilled records from third-party applications, and the ShinyHunters extortion crew is claiming the theft of 284 million entries. The pharmaceutical giant confirmed the intrusion in a securities filing.
The distributor said the breach was detected on August 25 and that the investigation remains in early stages. McKesson said the unauthorized access touched third-party apps tied to its Oncology and Multispecialty and Medical-Surgical business units, and that customers may see occasional service degradation.
ShinyHunters told BleepingComputer the entry came through vishing calls to employees. Stolen credentials then unlocked Okta single sign-on accounts, and the group moved into Salesforce and Snowflake environments, where it says it pulled about a terabyte of data in four days. It demanded $55M and gave McKesson 72 hours to respond, with no answer coming.
The claimed haul includes names, addresses, birth dates, Social Security numbers, patient IDs, Medicaid details, medication and allergy information, physician records, and employee data. The 284 million figure reflects database rows rather than individual patients, and none of the claims are independently verified.
McKesson said it does not believe customers need to take action and is not proactively disconnecting systems, while its security team and outside experts work to limit impact. The company has not determined whether the incident is material to its finances.
The breach lands as attackers keep targeting healthcare: medical device maker Boston Scientific disclosed its own global cyberattack days earlier.
