Key Takeaways
- McKesson confirmed unauthorized access and data exfiltration involving third-party applications, but its investigation remains at an early stage.
- ShinyHunters claims it obtained 284 million records linked to tens of millions of patients, not 284 million unique individuals.
- The reported voice-phishing attack highlights the risks surrounding enterprise identity controls, cloud applications, and healthcare data.
McKesson is investigating a cybersecurity incident involving unauthorized access to third-party applications and the exfiltration of data, following claims by ShinyHunters that the group stole 284 million patient records.
The distinction between records and people matters. ShinyHunters initially described the material as data on more than 284 million patient records, then clarified that the files were linked to tens of millions of patients. The exact number of affected individuals is not yet known. A single patient can have numerous records covering prescriptions, appointments, claims, diagnoses, shipments, and communications.
McKesson confirmed that it had activated its incident response procedures, brought in cybersecurity specialists, and started examining the nature and scope of the intrusion.
“McKesson is in the early stages of investigating a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data,” a McKesson spokesperson said. “Our teams are working with urgency and care to understand the nature and scope of the incident, support business continuity and minimize disruption.”
BleepingComputer also reported that McKesson had disclosed a cybersecurity incident tied to unauthorized access involving third-party applications. McKesson has not publicly validated ShinyHunters’ record count, every category of allegedly stolen information, or the group’s description of how access was obtained.
The claims are extensive. ShinyHunters says the dataset includes names, home addresses, dates of birth, phone numbers, email addresses, Social Security numbers, Medicaid numbers, patient IDs, and medical record numbers. It also allegedly contains diagnoses, allergies, medications, disabilities, appointment details, physician information, and patient notes.
More sensitive categories are reportedly present as well, including hospice information, terminal illness records, causes of death, autopsy details, sexual orientation, and disease-risk assessments such as cancer predictions. Prescription orders, invoices, billing details, delivery addresses, shipment dates, and tracking numbers are also among the claimed contents.
That combination could create unusually convincing fraud opportunities. A criminal who knows a person’s provider, medication, appointment history, and billing information can craft messages that look far more credible than ordinary spam. Fraudulent prescription notices, fake medical bills, insurance-themed phishing, and identity theft are among the practical risks.
Beyond patients, ShinyHunters claims it obtained employee information, physician and clinic records, and email communications between doctors and patients. The group said the communications involved email content but not attachments.
The incident was allegedly an identity-led intrusion rather than an exploit of an obscure technical vulnerability. ShinyHunters told the reporting publication that it voice-phished two employees before extracting information from Salesforce and Snowflake instances. That account has not been independently confirmed by McKesson, but it reflects a broader shift toward attacks that target trusted identities and cloud sessions.
Network perimeters are frequently bypassed when attackers successfully persuade employees to hand over credentials. Voice phishing can be particularly difficult to stop because it exploits urgency, authority, and normal support processes. Strong multifactor authentication can help, although organizations also need controls around account recovery, session tokens, unusual exports, privileged access, and third-party application connections.
The group is demanding $55,236,150 in exchange for not publishing the stolen files and says McKesson has not responded to its messages. The demand remains an attacker claim, and there is no public indication that McKesson intends to pay.
The incident arrives amid sustained pressure on healthcare organizations. The American Hospital Association characterized 2025 as a record year for healthcare breach volume, while TechTarget documented the largest healthcare breaches reported to the HHS Office for Civil Rights that year.
Under the HIPAA Breach Notification Rule, regulated entities generally face notification obligations when unsecured protected health information is breached. Large incidents affecting 500 or more individuals are also publicly reportable to HHS OCR. McKesson will first need to determine which systems, customers, data elements, and people were actually affected.
For enterprise security leaders, the immediate lesson centers on the connections among people, identities, applications, and centralized data stores. Third-party access reviews, phishing-resistant authentication, export monitoring, and rapid credential revocation can reduce exposure. For patients and healthcare partners, caution is warranted, but the confirmed scope still depends on McKesson’s continuing investigation.
⬇️