AI Stories on SHORT INFO are generated & curated with AI
2 linked sources 30 Aug, 12:12

Hackers claim theft of 284 million patient data records from McKesson

McKesson disclosed a cybersecurity incident in an SEC filing after the extortion group ShinyHunters claimed it stole 284 million patient-related data records via a vishing attack on employees. Per BleepingComputer and McKesson's SEC 8-K filing.

Healthcare and pharmaceutical distributor McKesson disclosed a cybersecurity incident in a Form 8-K filing with the SEC, saying it discovered the incident on August 25, 2026, and that its investigation remains in the early stages. The extortion group ShinyHunters told BleepingComputer it compromised employees' Okta single sign-on accounts through voice-phishing (vishing) social engineering, then accessed McKesson's Salesforce and Snowflake environments. ShinyHunters claims it exfiltrated about 1TB of data over four days (Aug 21-25) and that the Snowflake data contains approximately 284 million data records of patient-related information - though the group clarified to BleepingComputer this is a raw record count, not a confirmed number of unique patients. ShinyHunters says it demanded a $55,236,150 ransom with a 72-hour deadline, which McKesson did not meet. BleepingComputer has not independently verified ShinyHunters' claims, and McKesson has not publicly disclosed what data was stolen. Sources: BleepingComputer, McKesson SEC 8-K filing.

#cyber
Published on