01Summary
McKesson detected the intrusion on 25 August 2026 and disclosed it on 28 August. The incident involved third-party applications linked to customers in its Oncology & Multispecialty and Medical-Surgical units. ShinyHunters said it voice-phished several employees, exfiltrated data from 21 to 25 August, and demanded $55,236,150 with a 72-hour deadline. It claims 284 million rows of patient data, which is database rows rather than people. The stolen data included names, addresses, birth dates, SSNs, Medicaid/Medicare IDs, diagnoses, medications and billing data. Troy Hunt counted 6.4 million unique email addresses. McKesson gave an update on 8 September.
02Technical analysis
- Attack vector
- Voice phishing (vishing) of employees
- Initial access
- Social engineering
03Threat actor
Attribution sources
- ShinyHunters statements to BleepingComputer
04Victims and impact
Countries affected
- United States
05Data exposed
Data types
- Names
- Addresses
- Dates of birth
- Social Security numbers
- Medicaid/Medicare IDs
- Diagnoses
- Medications
- Billing and card data
06Timeline
- 2026-08-21Data exfiltration begins.
- 2026-08-25Intrusion detected; ransom demand sent.
- 2026-08-28McKesson discloses the incident.
- 2026-09-08McKesson issues an investigation update.
07Disclosure and media
Publishing organisations
- BleepingComputer
- HIPAA Journal
- Help Net Security
- Malwarebytes
09Sources
Official documents
- McKesson Form 8-K (Aug 2026)
References
- [1]HIPAA Journal: https://www.hipaajournal.com/mckesson-data-breach/
- [2]BleepingComputer: https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/









