McKesson confirms intrusion as hackers claim 284M records

Drug distributor McKesson confirmed an intrusion days before ShinyHunters claimed a 284-million-record haul from its cloud environments.

MedRisk Staff
By
2 Min Read

McKesson confirmed on August 28 that it detected a cybersecurity incident three days earlier, with unauthorized access to certain third-party applications and theft of data. The pharmaceutical distribution giant, which moves roughly a third of the prescription drugs sold in the United States, said an investigation with outside experts is underway.

Hours after the disclosure, the ShinyHunters extortion group claimed it pulled about 284 million records from McKesson’s Snowflake and Salesforce environments between August 21 and August 25. The group told CyberInsider the data is tied to tens of millions of patients, though the exact number of individuals remains unclear.

The attackers said they reached the systems by voice-phishing two employees for credentials. The claimed haul spans names, addresses, Social Security numbers, Medicaid numbers, diagnoses, medications, hospice and terminal illness records, causes of death, autopsy details, and disease-risk assessments, along with prescription, billing, and shipment data, employee files, and physician and clinic records.

ShinyHunters is demanding roughly $55M and has posted a final warning with a September 1 deadline, threatening full publication of the data. McKesson has not publicly confirmed the claim’s accuracy. The listing is the group’s second healthcare strike in days: it also posted radiation oncology equipment maker Elekta and, in mid-August, leaked 7.1 million records claimed to come from medical device maker Baxter.

Patients who may be affected should watch for phishing, fraudulent billing, and prescription-related scams, and consider identity theft protections.

Share This Article