EARF
United States Flag
United StatesNorth America
Japan Flag
JapanAsia
Italy Flag
ItalyEurope
Netherlands Flag
NetherlandsEurope
United Kingdom Flag
United KingdomEurope
EARFSTAGE
EARFSTAGEFestivals and live sets
METAR | EARF
EARFWeatherLive weather stations
EARFWiki
EARFWikiCountries and public records
EARFguessGuess where on Earth
/data-breach/2026-mckesson-shinyhunters-breach
012/430

File EL-0419CriticalOngoingData Breach / Social Engineering / Third-Party Application Compromise

McKesson Data Breach

Also filed as McKesson ShinyHunters Hack

ShinyHunters voice-phished McKesson employees, stole about 1 TB of patient and business data from third-party applications, and demanded more than US$55 million.

  • #healthcare
  • #phi
  • #shinyhunters
  • #vishing
  • #extortion
  • #united-states
  • #sec-8-k
Notoriety9/10
Event
21 Aug 2026
Disclosed
28 Aug 2026
Target
McKesson
Actor
ShinyHunters
Scale
284.0M records
Status
Ongoing

01Summary

McKesson detected the intrusion on 25 August 2026 and disclosed it on 28 August. The incident involved third-party applications linked to customers in its Oncology & Multispecialty and Medical-Surgical units. ShinyHunters said it voice-phished several employees, exfiltrated data from 21 to 25 August, and demanded $55,236,150 with a 72-hour deadline. It claims 284 million rows of patient data, which is database rows rather than people. The stolen data included names, addresses, birth dates, SSNs, Medicaid/Medicare IDs, diagnoses, medications and billing data. Troy Hunt counted 6.4 million unique email addresses. McKesson gave an update on 8 September.

02Technical analysis

Attack vector
Voice phishing (vishing) of employees
Initial access
Social engineering

03Threat actor

Attribution sources

  • ShinyHunters statements to BleepingComputer

04Victims and impact

Countries affected

  • United States

05Data exposed

Data types

  • Names
  • Addresses
  • Dates of birth
  • Social Security numbers
  • Medicaid/Medicare IDs
  • Diagnoses
  • Medications
  • Billing and card data

06Timeline

  1. 2026-08-21Data exfiltration begins.
  2. 2026-08-25Intrusion detected; ransom demand sent.
  3. 2026-08-28McKesson discloses the incident.
  4. 2026-09-08McKesson issues an investigation update.

07Disclosure and media

Publishing organisations

  • BleepingComputer
  • HIPAA Journal
  • Help Net Security
  • Malwarebytes

08Related files

Related events

  • 2026-shinyhunters-fbijobs-breach-claim

09Sources

Official documents

  • McKesson Form 8-K (Aug 2026)

References

  1. [1]HIPAA Journal: https://www.hipaajournal.com/mckesson-data-breach/
  2. [2]BleepingComputer: https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
Fact sheetEL-0419

Dates

Event
21 Aug 2026
Started
21 Aug 2026
Ended
25 Aug 2026
Duration
5 days
Discovered
25 Aug 2026
Disclosed
28 Aug 2026
Ongoing
Yes

Target

Organisation
McKesson Corporation
Type
Healthcare Distribution Company
Sector
Healthcare
Country
United States

Actor

Name
ShinyHunters
Type
Criminal Gang
Motivation
Extortion (demanded US$55,236,150)
Attribution
Medium
Arrested
No
Convicted
No

Data

Records
284,000,000
Volume
About 1 TB
Sensitivity
Critical

Money

Ransom asked
$55,236,150

EARFLeaks documents publicly known security incidents. It does not host, store or distribute leaked data.

© 2026 EARF. All rights reserved.