McKesson, a major healthcare and pharmaceutical distribution company, has disclosed a cybersecurity incident involving unauthorized access to third-party applications. The ShinyHunters extortion group has claimed responsibility, alleging they stole 284 million patient data records. The breach involves sensitive patient information, making it one of the largest healthcare data theft incidents. McKesson confirmed unauthorized access occurred but has not yet provided full details on the scope of the breach. ShinyHunters is a well-known threat actor group associated with large-scale data theft and extortion operations targeting high-value organizations. The incident raises significant concerns about third-party application security in the healthcare sector. Regulatory and legal implications are likely given the scale of the alleged data theft and the sensitive nature of patient records.
ShinyHunters conducted voice phishing (vishing) social engineering attacks against multiple McKesson employees using the domain 'mckesson[.]claims' to impersonate McKesson's help desk and IT teams. This is part of a broader campaign where ShinyHunters registers .claims TLD domains containing target company names or abbreviations. The vishing attacks led to the compromise of multiple employees' Okta single sign-on (SSO) accounts. Using the compromised Okta credentials, attackers accessed McKesson's Salesforce and Snowflake cloud environments. The threat actor claims to have fully compromised the Salesforce environment, including support cases. Approximately 1TB of data was exfiltrated over four days between August 21 and August 25, 2026. The stolen Snowflake data allegedly contains approximately 284 million data records (raw row count, not unique individuals) of patient-related information. Compromised data types include: names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information, physician information, information on deceased and terminally ill patients, prescriptions and medication shipments, invoices, employee information, Salesforce records, internal communications, and healthcare provider/clinic data. ShinyHunters demanded a ransom of $55,236,150 with a 72-hour response window, which McKesson did not respond to. The incident was discovered by McKesson on August 25, 2026, and disclosed via SEC Form 8-K filing.
1. Be aware of and train employees against vishing (voice phishing) social engineering attacks, particularly those impersonating internal IT/help desk teams. 2. Monitor for suspicious domain registrations following the pattern 'companyname[.]claims' or similar TLD abuse used to impersonate your organization. 3. Implement phishing-resistant multi-factor authentication (MFA) for Okta and all SSO platforms to reduce risk from credential compromise via social engineering. 4. Monitor Okta logs for anomalous login activity, unusual access patterns, or logins from unexpected locations/devices. 5. Audit and restrict access to Salesforce and Snowflake environments; apply least-privilege principles. 6. Enable and review data exfiltration alerts in Snowflake and Salesforce for large-scale data transfers. 7. Healthcare organizations should review Health-ISAC warnings about rising ShinyHunters social engineering attacks targeting cloud and SaaS platforms. 8. Establish and rehearse incident response protocols for social engineering and cloud-based data theft scenarios. 9. Verify caller identity through out-of-band channels before granting any IT assistance or credential resets. 10. Implement network-level and endpoint controls to detect and alert on bulk data transfers exceeding normal thresholds.
mckesson[.]claims (phishing domain used in vishing campaign)