// 1 CRITICAL · 1 ZERO-DAY · 4 CVE · 3 EXPLOIT IN THE LAST 24H
McKesson disclosed a security incident involving unauthorized access to third-party applications. The ShinyHunters group claims to have stolen 284 million records.

McKesson, one of the largest pharmaceutical distributors in the United States, disclosed a security incident on August 28, 2026, discovered three days earlier. The ShinyHunters group claimed responsibility for the attack, asserting it exfiltrated roughly 284 million healthcare records during four days of dwell time in the systems. The ransom demand stands at $55,236,150, with a 72-hour deadline that McKesson did not meet.

Key Takeaways
  • McKesson discovered the incident on August 25 and disclosed it publicly via a Form 8-K filed with the SEC on August 28, without determining materiality.
  • ShinyHunters claims it used vishing against employees to compromise Okta SSO accounts, then used those to access Salesforce and Snowflake environments.
  • The group asserts it exfiltrated approximately 1 TB of data in four days, clarifying that the 284 million figure represents records or database rows, not unique individuals.
  • McKesson has not confirmed the attack vector, which third-party applications were involved, or the categories of data exposed.

The SEC Disclosure: Obligations and Caveats

McKesson's communication follows the mandatory path for public companies. The Form 8-K filed on August 28, 2026, reports the August 25 discovery and the immediate activation of incident response protocols, including the engagement of external cybersecurity experts.

The wording is standard for cautious disclosures: "As of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations." McKesson added, in a customer statement cited by BleepingComputer, that "upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to assist in our response."

This communications architecture — immediate disclosure but deferred materiality — reflects the tension between Securities and Exchange Commission obligations and the slower pace of forensic investigations. The company must inform the market within four business days of discovering a significant event, but assessing the economic impact takes longer.

ShinyHunters' Claim: Vishing, SSO, and Cloud

The ShinyHunters group provided BleepingComputer with a detailed technical narrative, not independently verified. According to the claim, initial access occurred via voice phishing — vishing — against McKesson employees, resulting in the compromise of Okta Single Sign-On accounts.

From there, the group asserts, the accounts were used to access Salesforce and Snowflake environments housing healthcare databases. Exfiltration allegedly took place between August 21 and August 25, 2026, in a four-day window estimated at roughly 1 TB of volume.

The domain mckesson[.]claims was cited by an anonymous BleepingComputer source as an element of the attack. This correlation has not been independently verified. The pattern — organization name with a .claims extension — was documented by ReliaQuest in a broader ShinyHunters campaign, as reported in a subsequently deleted X post.

Health-ISAC has classified this pattern as a recurring TTP in 2026: "SSO is the control plane, and ShinyHunters' leverage is created through data theft at cloud scale." The described chain is pure social engineering: no confirmed technical exploit, but identity compromise as the central element for moving across SaaS platforms.

The Ransom Numbers and the Record Problem

ShinyHunters set the ransom at $55,236,150, with a 72-hour deadline that expired without a response from McKesson. The group offered no explanation for the calculation methodology.

The 284 million record figure requires decoding: ShinyHunters itself clarified to BleepingComputer that these are records or database rows, not unique individuals. CyberInsider received data samples from the group and deemed them consistent with the claims, but the samples have not undergone independent verification.

This distinction is critical for the healthcare sector. A single patient can generate dozens of records across different systems — prescriptions, billing, specialist visits — so the number of human entities involved is potentially far lower than 284 million. McKesson has disclosed neither the number of individuals nor the categories of information exposed.

284 million: records/database rows claimed by ShinyHunters, not unique individuals

What Changes

The McKesson incident fits a pattern of ShinyHunters attacks against the healthcare sector in 2026, documented by Health-ISAC. The recurring method — social engineering against SSO identities, followed by lateral movement to cloud platforms — exploits the centralization of modern architectures.

McKesson has not confirmed the attack vector or the compromise of Okta, Salesforce, or Snowflake. ShinyHunters' claims on these specific points remain unverified. The company has activated response protocols and investigations with external experts, but has not disclosed which third-party applications were involved.

The lack of a materiality determination in the Form 8-K leaves the question of economic and regulatory impact open. The SEC may assess whether subsequent updates modify this position.

Verifiability Limits

This article relies primarily on BleepingComputer as the primary structured source. ShinyHunters' claims — including the vishing method, Okta account compromise, access to Salesforce and Snowflake, the 1 TB volume, and the 284 million records — have not been independently verified. McKesson has not confirmed these elements.

The domain mckesson[.]claims was cited by an anonymous BleepingComputer source; this correlation has not been independently verified. The data samples examined by CyberInsider came directly from the attacker, carrying a risk of selection or manipulation.

Secondary sources — tech-insider.org, we-fix-pc.com, the420.in, cybernews.com — repackage or duplicate BleepingComputer's content without adding original verification elements. The source cyberinsider.com received samples directly from ShinyHunters, with potential bias.

Information has been verified against cited sources and is current as of publication.

Sources


Sources and references
  1. bleepingcomputer.com
  2. cyberinsider.com
  3. cybernews.com
  4. tech-insider.org
  5. we-fix-pc.com
  6. the420.in
  7. wiz.io