McKesson Corporation has confirmed hackers broke into its systems and stole company and patient data, and the extortion group ShinyHunters is demanding $55 million to keep it from being published. McKesson has not confirmed the ransom figure or the exact number of people affected, but the hackers say they took roughly 284 million rows of records, including Social Security numbers, prescription and billing details, and protected health information. The pharmaceutical and medical-supply distributor disclosed the intrusion to federal regulators on Aug. 25, 2026.
A vishing call, a spoofed domain and stolen Okta logins
The break-in did not start with malware. According to security reporting on the incident, attackers used voice phishing — phone calls impersonating IT staff — paired with a spoofed domain, mckesson[.]claims, to trick employees into handing over credentials for McKesson’s Okta identity system. Those stolen logins gave the attackers a path into McKesson’s Salesforce and Snowflake cloud environments, where much of the company’s customer and business data was stored.
Data exfiltration ran from roughly Aug. 21 to Aug. 25, 2026, pulling an estimated 1 terabyte of files before McKesson’s security team detected the activity, according to BleepingComputer’s reporting on the attack chain. That is a four-day window in which a single set of compromised employee credentials reached two of the company’s core cloud platforms.
What McKesson’s SEC filing does and doesn’t say
McKesson disclosed the incident to the Securities and Exchange Commission in a Form 8-K dated Aug. 25, 2026, the same day it says the activity was discovered. The filing states plainly that “an investigation of the incident is in its early stages” and that, as of the filing date, McKesson “has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company.” Separately, a company spokesperson said McKesson’s investigation to date had linked the activity to subsets of its Oncology & Multispecialty and Medical-Surgical business units.
That is a narrower claim than the one ShinyHunters is making. McKesson has said only that certain third-party applications were accessed without authorization; it has not confirmed the 284 million figure, has not confirmed the ransom demand, and has not said how many patients, employees or physician customers are in the affected data. McKesson is one of the largest pharmaceutical distributors in the country, supplying drugs and supplies to hospitals, pharmacies and physician practices nationwide, which is part of why a breach touching its Salesforce and Snowflake environments could reach so many downstream patients who never dealt with McKesson directly.
The $55,236,150 demand ShinyHunters made
ShinyHunters, a hacking group with a long record of extorting companies over stolen cloud data, is demanding a specific figure: $55,236,150, according to reporting that reviewed the group’s ransom note. TechCrunch, which first reported the group’s claims, described the demand as $55 million and said McKesson declined to answer questions about it, including how the company planned to respond.
McKesson said its services kept running throughout the incident and that it had reasonable assurance there was no continuing unauthorized access to its systems. The company has not said whether it intends to pay, and no deadline extension or payment has been publicly reported since the demand was made.
6.4 million email addresses and the scope still being counted
Independent verification has so far landed on a smaller, more concrete number than ShinyHunters’ claim. HaveIBeenPwned, the breach-notification database run by security researcher Troy Hunt, logged 6.4 million unique email addresses tied to the leaked data set, alongside names, dates of birth, phone numbers, employers and physical addresses. Hunt’s listing describes the campaign against McKesson as a “pay or leak” extortion operation, the same model ShinyHunters has used against other companies whose stolen cloud data it has published or threatened to publish when a ransom went unpaid.
HIPAA Journal reported that the wider haul the hackers advertised also included health insurance identifiers, diagnoses, medications and lab test results tied to specific patients, on top of employee records and physician-office contact details pulled from McKesson’s Salesforce environment. Those categories go well beyond the email addresses HaveIBeenPwned has confirmed, and none of them has been independently verified the way the email list has.
The gap between 284 million claimed rows and 6.4 million confirmed email addresses reflects how the totals hacking groups advertise, including ShinyHunters’ own past claims against other companies, often count repeated or duplicate database rows rather than distinct people. McKesson has not said when its investigation will conclude or when it expects to notify regulators and affected individuals directly, so the true number of patients whose information is at risk is still unknown almost a month after the intrusion began.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- A geomagnetic storm is forecast to hit Earth today, pushing the northern lights unusually far south
- A recalled pill hid a stimulant dose linked to heart attacks and death
- Four U.S. startups fired up their first small nuclear reactors, aiming to power AI data centers on-site
- Card skimmers hidden on gas pumps and ATMs are draining accounts, and here’s the tell