McKesson Corporation, the pharmaceutical distributor that moves roughly a third of prescription drugs sold in the United States, confirmed on August 28, 2026, that it suffered a cybersecurity incident involving unauthorized access to third-party applications. In a Form 8-K filed with the U.S. Securities and Exchange Commission, McKesson said it discovered the incident on August 25, 2026, and that its investigation “remains in the early stages,” with updates being posted to the company’s website.
Hours after McKesson’s disclosure, the extortion group ShinyHunters told BleepingComputer it had exfiltrated approximately one terabyte of data from the company’s Salesforce and Snowflake environments over a four-day window between August 21 and August 25, 2026. According to the group, initial access came through vishing attacks that compromised multiple employees’ Okta single sign-on accounts, which were then used to reach the Salesforce and Snowflake platforms.
ShinyHunters claimed the stolen data includes roughly 284 million patient-related records, and said it contacted McKesson after completing the theft to demand a ransom of $55,236,150, giving the company 72 hours to respond. The group said McKesson did not negotiate or respond to the demand.
Part of a Broader Pattern Targeting Healthcare and SaaS Platforms
The McKesson incident is the latest in an ongoing wave of data-theft attacks attributed to ShinyHunters against healthcare and health-technology organizations, several of which have involved compromised third-party SaaS and cloud-data platforms rather than direct breaches of core clinical systems. As with earlier incidents in this pattern, the exposure risk here centers on identity providers and cloud data warehouses that sit adjacent to, but outside, an organization’s primary operational infrastructure — a distinction that matters for how healthcare and pharmaceutical enterprises prioritize identity security and third-party risk monitoring alongside traditional network defenses.
McKesson has not confirmed the scope of data exposed or verified ShinyHunters’ record-count claim. The company said additional updates would be provided as the investigation progresses.

Leave a Reply