READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 110+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

McKesson Confirms Data Theft as Hackers Demand $55 Million, Claim 284 Million Patient Records Stolen

McKesson Confirms Data Theft as Hackers Demand $55 Million, Claim 284 Million Patient Records Stolen
McKesson detected hackers in its systems on August 25, 2026, and confirmed data was stolen from its Oncology and Medical-Surgical units. The ShinyHunters extortion group says it grabbed 284 million records and wants $55,236,150 to stay quiet, but McKesson never paid and the real number of affected patients is still unknown.

McKesson discovered hackers had broken into its systems on August 25, 2026, according to a Form 8-K filing with the Securities and Exchange Commission cited by Help Net Security. The pharmaceutical and medical-supply giant disclosed the breach publicly on August 28, and it's still working out how bad the damage is.

McKesson's chief information and technology officer, Francisco Fraga, said the company has verified that hackers accessed "certain third-party applications" and exfiltrated data tied to a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units, according to Help Net Security and Fierce Healthcare. McKesson says its distribution centers are still shipping products and taking orders, and it has "reasonable assurance" there's no ongoing unauthorized activity in its systems.

The ShinyHunters extortion group, which claimed responsibility for the attack in conversations with BleepingComputer, says it stole roughly 284 million records totaling about a terabyte of data over four days, from August 21 to 25. The group told BleepingComputer it got in by voice-phishing McKesson employees, then hijacked Okta single sign-on credentials to reach the company's Salesforce and Snowflake cloud environments, according to Malwarebytes and Help Net Security.

ShinyHunters says the stolen data includes names, home addresses, birth dates, Social Security numbers, patient IDs, Medicaid details, medical record numbers, medication and allergy information, physician information, internal Salesforce records, and McKesson employees' own home addresses, according to Help Net Security.

The 284 million number is misleading. HIPAA Journal's Steve Alder made the distinction that matters here: that figure reflects database rows, not unique patients. One person's record could span dozens of rows across prescriptions, diagnoses, and provider notes. It's still a massive breach, Alder wrote, but 284 million is not 284 million people.

None of ShinyHunters' claims have been independently verified in full. Help Net Security stated plainly that the hackers' account of what they took "have not been independently verified." TechCrunch said it checked a small subset of the sample data the group provided against public records and found it consistent, and CyberInsider said it reviewed privately-shared samples that appeared to match the group's description. That's evidence the breach is real and serious. It is not confirmation of the full scope ShinyHunters is claiming.

Ransom demand. ShinyHunters told BleepingComputer it contacted McKesson after finishing the theft on August 25 and demanded exactly $55,236,150, giving the company 72 hours to pay before the group would leak the files. According to Help Net Security, McKesson never responded. McKesson spokesperson Kristina Chang would not answer TechCrunch's questions about what the hackers demanded or how many people were affected.

McKesson has not said whether it engaged with the hackers at all, publicly or privately, and has not confirmed the ransom figure ShinyHunters cited. That's a real gap in the public record. Companies facing extortion demands often stay silent on negotiations for legal and security reasons, but it means the public has only the hackers' word on the terms.

Pattern in healthcare breaches. ShinyHunters has hit a string of healthcare and medical-device companies over the past year, including Medtronic, Abbott Laboratories, iRhythm, AdaptHealth, and DentaQuest, according to HIPAA Journal. TechCrunch noted Boston Scientific was hit by a separate cyberattack the week before McKesson's breach became public, knocking much of that company's network offline.

Separately, and unrelated to the McKesson intrusion, CareCloud disclosed to the California Attorney General that a March 2026 breach of one of its Amazon Web Services environments has ballooned in scope. Fox News reported CareCloud now says more than 3.75 million people were affected, up from an initial disclosure of hundreds of thousands, after hackers had access between March 10 and 16, 2026. CareCloud provides electronic medical record technology to tens of thousands of U.S. healthcare providers, meaning patients who never signed up for the company directly could still be exposed through their doctor's office.

McKesson has not said whether the SEC filing will be updated to reflect the incident as "material" under securities disclosure rules, a determination the company says it has not yet made. Whether McKesson paid, is paying, or plans to pay any ransom remains unknown. The actual number of patients whose Social Security numbers and medical histories are now sitting on a hacker's leak site is still an open question McKesson has declined to answer.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center-left
TechCrunchHackers claim millions of patient records stolen during data breach at healthcare giant McKesson
right
noticias.foxnewsHealthcare data breach exposes 3.75M patient records
unknown
HIPAA JournalShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson
unknown
MalwarebytesMcKesson confirms cyber incident after ShinyHunters claims patient-data theft
unknown
Help Net SecurityShinyHunters claims it stole 284 million patient records from McKesson
unknown
Ground NewsHackers Claim Millions of Patient Records Stolen During Data Breach at Healthcare Giant McKesson
unknown
Fierce HealthcareMcKesson confirms cybersecurity incident as hackers claim millions of patient records stolen