
The ShinyHunters threat group claims it compromised McKesson and obtained data on over 284 million patient records, including highly sensitive medical, identity, prescription, and healthcare provider information.
CyberInsider reviewed samples privately provided by the threat actor that appear consistent with the types of information described in the data breach claims.
Update: Following a request for a statement, a spokesperson for McKesson confirmed the incident to CyberInsider, saying that an investigation into its scope has been launched.
McKesson is in the early stages of investigating a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data. Upon discovery, we immediately activated our incident response protocols, launched an investigation and engaged leading cybersecurity experts.
We take the privacy and security of our customers, partners, their patients and our employees very seriously. Our teams are working with urgency and care to understand the nature and scope of the incident, support business continuity and minimize disruption.
Our investigation remains ongoing, and we are committed to providing accurate information and updates as they become available.
-McKesson spokesperson
McKesson Corporation is one of the largest healthcare companies in the United States and a major distributor of pharmaceuticals, medical supplies, and healthcare technology services. The company operates across a vast network of pharmacies, hospitals, clinics, physicians, manufacturers, and other healthcare organizations.
Update: ShinyHunters has further clarified to CyberInsider that 284 million records were obtained, linked to tens of millions of patients, but the exact number of people in the breach is not yet known.
According to ShinyHunters, the allegedly stolen patient data includes:
- Identity and contact information: full names, home addresses, dates of birth, phone numbers, email addresses, and Social Security numbers.
- Healthcare identifiers: patient IDs, medical record numbers (MRNs), and Medicaid numbers.
- Medical information: illnesses and diagnoses, allergies, medications, disabilities, patient notes, appointment details, and physician information.
- Highly sensitive records: hospice and terminal illness information, causes of death, autopsy details, sexual orientation, and other personal status information.
- Predictive health data: disease-risk assessments, including cancer predictions linked to individual patients.
- Prescription and billing records: medication orders, invoice and billing information, shipment addresses, dates, and tracking numbers.
Beyond patient information, ShinyHunters says the dataset contains employee records with names, addresses, email addresses, phone numbers, departments, and job roles, as well as information about physicians and clinics using McKesson services. Doctor and patient communications have also been exfiltrated, though the threat actors said this concerns only email content, not attachments.
The physician data allegedly includes names, contact details, practice locations, and addresses, while clinic-related records reportedly reveal locations, employee counts, and other organizational information.

CyberInsider
The threat actor told CyberInsider that it accessed McKesson’s systems by voice-phishing two employees and then extracting data from Salesforce and Snowflake instances.
The data extortionists now demand a ransom payment of $55,236,150 not to release the stolen files, but said McKesson has not responded to their messages yet.
People concerned that their healthcare information may have been exposed in this incident should be especially vigilant against phishing messages, fraudulent medical billing attempts, prescription-related scams, and identity theft.
Article updated at 3:30 PM ET to add confirmation from McKesson that an investigation into unauthorized systems access is underway.
Article updated at 6:07 PM ET after ShinyHunters further clarified to CyberInsider that 284 million records were obtained, linked to tens of millions of patients, but the exact number of people in the breach is not yet known.






Leave a Reply