McKesson, one of the largest health care distribution and services companies in the country, has confirmed a cybersecurity incident that a well-known extortion group claims exposed hundreds of millions of records tied to patients, employees and health care providers. The company disclosed the breach in late August after the group ShinyHunters listed McKesson on its data leak site and threatened to publish stolen files. McKesson’s investigation remains in its early stages, and the exact number of people affected has not been independently confirmed. The incident adds McKesson to a growing list of health care organizations hit by large-scale data theft in 2026, a sector that has become a frequent target because of the volume of sensitive personal and medical information its systems hold. McKesson is one of the largest pharmaceutical distributors in the United States, supplying medications and medical supplies to hospitals, pharmacies and oncology practices nationwide, which means a breach of its systems can touch patient data far beyond the company’s own direct customers.
Vishing Calls Opened a Path Into McKesson’s Systems
According to the attackers’ own account, the breach began with voice phishing calls, commonly called vishing, targeting multiple McKesson employees. Vishing attacks typically involve a caller impersonating internal IT staff or a trusted vendor to trick an employee into handing over login credentials or approving a fraudulent access request. ShinyHunters told researchers it used compromised credentials tied to McKesson’s Okta single sign-on system to gain broader access, then moved into the company’s Salesforce and Snowflake environments, two platforms widely used to store customer and business data. Vishing has become a preferred entry point for several extortion groups in recent years, in part because it targets employees directly rather than relying on software vulnerabilities that companies can patch.
A Claim of 284 Million Records, Not Necessarily 284 Million People
ShinyHunters has claimed it exfiltrated roughly 284 million data records from McKesson, a figure the group itself later clarified refers to a raw count of individual data lines rather than the number of unique people affected. The distinction matters because a single patient’s file can generate many separate records, covering appointments, prescriptions, billing and provider notes. ShinyHunters has acknowledged it has not fully analyzed the stolen data and does not know how many distinct individuals are represented in the files it took, leaving the ultimate scope of the breach an open question even for the attackers. Security researchers caution that raw record counts published by extortion groups are frequently inflated or duplicated, and that confirmed figures typically emerge only after a company’s own forensic investigation concludes, a process that can take months.
What the Published Data Has Shown So Far
Security researchers who reviewed data published by ShinyHunters identified 6.4 million unique email addresses tied to patients, employees, health care providers and marketing recipients. The exposed information reportedly includes names, physical addresses, genders, dates of birth, phone numbers and employer details, along with appointment dates and clinical notes. Roughly one terabyte of data is believed to have been taken between August 21 and August 25, based on the timeline attackers described to reporters, though McKesson has not publicly confirmed every detail of that account. Researchers who examined samples of the leaked files said the data appeared consistent with genuine McKesson records rather than fabricated or recycled material from earlier breaches, lending credibility to at least the core of the attackers’ claims.
A Ransom Demand With a 72-Hour Deadline
After completing the data theft, ShinyHunters contacted McKesson with a ransom demand of more than $55 million, giving the company 72 hours to respond before threatening to release the stolen files. McKesson has not disclosed publicly whether it engaged with the extortion attempt or made any payment. The tight deadline is consistent with tactics ShinyHunters and similar groups have used in other high-profile extortion campaigns, pressuring victims to negotiate quickly rather than conduct a full forensic review before deciding how to respond. Cybersecurity specialists generally advise against paying such demands, noting that payment does not guarantee stolen data will be deleted and can encourage further attacks against the same organization.
An Oncology Network Adds to the Sensitivity of the Data
Part of what makes the McKesson breach notable is the company’s reach into oncology care through a specialty network that supports thousands of cancer treatment providers. Data reportedly exposed in the incident includes clinical details tied to that oncology business, including information about the locations of patients’ cancers, a category of medical information considered especially sensitive. The breach was highlighted by TechCrunch as among the most significant health care data incidents of 2026, alongside additional reporting from HIPAA Journal and BleepingComputer. Health care records are frequently targeted by extortion groups because they combine financial details with clinical history that cannot be changed the way a password or credit card number can, making the data valuable on criminal marketplaces well after a breach is disclosed. Patients and providers affected by the incident will likely not know the full extent of what was exposed until McKesson completes its investigation and issues formal notifications, a process that in comparable health care breaches has sometimes taken several months to finish.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview
- The FBI tells phone owners to delete these toll-payment texts draining accounts nationwide
- Herbal supplements are landing Americans in the hospital with liver damage, doctors warn
- Long-term use of common heartburn pills is linked to kidney and dementia risk
- 9 pickup trucks with a reputation for falling apart after 100,000 miles