McKesson suffers a cyber attack: data of 284 million patients potentially compromised
McKesson, one of the leading drug distributors and healthcare service providers in the United States, has reported a cyber incident that led to unauthorized access to third-party applications and data theft. The ShinyHunters ransomware group has claimed responsibility for the attack, stating that they stole 284 million patient records.
The incident was initially reported by CyberInsider and later confirmed by McKesson in a Form 8-K filing with the U.S. Securities and Exchange Commission (SEC). The company discovered the incident on August 25, 2026, but the investigation is still in its early stages.
McKesson stated that it has not yet determined whether the incident is material or whether it has had, or is reasonably likely to have, a material impact on the company, including its financial condition or operating results. However, the company warned that customers may experience intermittent service degradation, although it is not proactively disconnecting systems within its environment.
In a separate note to customers, McKesson confirmed that the incident involved third-party applications and unauthorized access and data exfiltration. "We take the security and privacy of our partners, customers, and their patients very seriously. Upon discovering the incident, we immediately activated our incident response protocols, initiated an investigation, and engaged leading cybersecurity experts to assist in our response," reads McKesson's note.
ShinyHunters claims responsibility for the attack
The ShinyHunters ransomware group told BleepingComputer that it was behind the attack, claiming to have gained access after conducting social engineering attacks based on vishing against multiple McKesson employees. ShinyHunters did not provide many technical details about the social engineering attacks, including the domains used during the campaign. However, BleepingComputer learned from another source that the threat actors used the domain mckesson.claims as part of the attack.
This domain corresponds to a recently documented ShinyHunters campaign by ReliaQuest's threat research team, which stated that the ransomware group was registering .claims domains containing the names or abbreviations of target companies to impersonate their help desks and IT teams.
"ReliaQuest is monitoring a widespread ShinyHunters campaign using domains that follow the company.claims pattern. These domains incorporate the name or abbreviation of the target organization under the .claims TLD," ReliaQuest stated in a now-deleted post on X.
Technical details of the attack
ShinyHunters told BleepingComputer that the vishing attacks led to the compromise of multiple Okta single sign-on employee accounts, which they then used to access the company's Salesforce and Snowflake environments. The threat group claims to have completely compromised the Salesforce environment, including support cases. The threat actors also claimed to have stolen a much larger collection of 284 million patient-related data records from Snowflake.
According to ShinyHunters, the threat actors exfiltrated approximately 1TB of data in four days, between August 21 and 25. The group states that the stolen data contains information related to 284 million patient-related data records. However, this does not mean that the breach affected 284 million patients. The figure is actually a raw count of approximately 284 million data records, or rows, rather than a count of unique individuals.
The threat actors told BleepingComputer that they have not fully analyzed the stolen data and do not know how many unique individuals are affected. They also stated that they have not yet sold the data but plan to do so in the future.
The stolen data includes names, addresses, phone numbers, dates of birth, medical record numbers, and treatment information. The threat actors claim to have accessed data from multiple hospitals and healthcare providers.
Economic losses and market impact
The economic losses resulting from data breaches in the healthcare sector are significant. According to the Ponemon Institute, the average cost of a data breach in the healthcare sector is $10.10 million, nearly double the average of other sectors. This includes direct costs such as victim notifications and fines, but also reputational damage and loss of patient trust.
McKesson, with an annual revenue of over $260 billion, is one of the largest companies in the healthcare sector. The breach could have significant repercussions on its market position, especially if the sensitive patient data is used for medical or identity fraud, as has happened in previous attacks on healthcare organizations.
Regulatory responses and legal challenges
The incident raises important regulatory issues, particularly regarding compliance with privacy laws such as the Health Insurance Portability and Accountability Act (HIPAA) in the United States. Regulatory authorities, including the Department of Health and Human Services (HHS), are likely closely monitoring the situation to assess whether McKesson has met data security requirements.
In case of HIPAA violation, McKesson could face substantial fines, in addition to potential lawsuits from patients whose data has been compromised. Healthcare companies are required to implement adequate measures to protect protected health information (PHI), and violations can result in penalties of up to $1.5 million per violation.
In addition to internal legal challenges, McKesson may also face investigations by European authorities if data from European patients has been involved, in violation of the General Data Protection Regulation (GDPR). Fines for GDPR violations can reach up to 4% of the company's global revenue.
Lessons learned and response strategies
The episode underscores the importance of proactive incident management. Healthcare organizations must be ready to respond quickly to breaches, including activating incident response teams, transparent communication with stakeholders, and engaging legal and security experts.
An effective incident response strategy includes network segmentation to limit access to sensitive data, implementation of advanced monitoring solutions to detect anomalous activity, and adoption of robust backup and recovery plans to minimize service disruptions.
Organizations should also consider purchasing data breach insurance, which can help cover legal and notification costs. However, these policies often require that companies demonstrate that they have implemented adequate security measures before the breach.
The future of security in the healthcare sector
The attack on McKesson is a reminder that the healthcare sector must adopt a more holistic approach to cybersecurity. This includes not only investments in technology but also continuous training of staff to recognize and resist social engineering techniques.
Emerging solutions such as artificial intelligence and machine learning can play a crucial role in detecting threats in real-time and automating responses. However, these technologies must be integrated into a broader security governance framework that includes clear policies, well-defined procedures, and a corporate culture that prioritizes security.
Finally, collaboration between healthcare companies, governments, and security experts is essential to address growing threats. Information sharing, best practices, and resources can help create a safer ecosystem for all participants.
Editorial Note and Disclaimer
The guides and content published on GoYou are the result of independent research and analysis activities, for informational, educational, and in-depth purposes.
GoYou does not constitute a journalistic publication nor an editorial product pursuant to Law No. 62/2001 and does not engage in real-time information activities.
The GoYou project does not provide professional, technical, legal, or financial advice and disclaims all responsibility for the improper use of the information published.
In the Crypto sector, every investment involves risks: readers are invited to always inform themselves autonomously before making any decision.