ThreatPaper
Data BreachExtortion & BlackmailSocial EngineeringCritical

McKesson Data Breach: ShinyHunters, One Phone Call, and 284 Million Rows of Patient Data

By Sethu Satheesh · 11 Sept 2026 · 19 min read

Threat Actor: ShinyHunters (self-claimed; overlaps Google's UNC6040/UNC6240 clusters) · Target: McKesson Corporation — Oncology & Multispecialty and Medical-Surgical business units; patients of its provider customers

Source: www.sec.gov


Executive Summary

On 25 August 2026, McKesson Corporation, the largest pharmaceutical distributor in the United States, discovered what it describes as "a cybersecurity incident targeting employee corporate accounts" that resulted in "unauthorized access to certain third-party applications and the exfiltration of certain data". The company's own investigation places the intrusion between 20 and 25 August. On 28 August it filed a Form 8-K under Item 7.01, Regulation FD, stating that it had "not determined that the incident is material", and posted a customer notice. On 29 August it narrowed the affected data to "a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units". On 8 September it posted a substitute Notice of Data Breach conceding that protected health information, Social Security numbers, payment card numbers and banking details "may have been impacted", and offering two years of credit monitoring.

The extortion group ShinyHunters claimed the attack the same day McKesson disclosed it. According to the group's account to BleepingComputer, its operators voice-phished several McKesson employees, took over their Okta single sign-on accounts, used those sessions to reach McKesson's Salesforce and Snowflake environments, and exfiltrated about a terabyte over four days, including roughly 284 million rows from Snowflake. The group demanded $55,236,150 within 72 hours and says McKesson did not respond. None of the mechanism has been confirmed by McKesson, which has not named any application, any data type it has verified as taken, or any count of affected people.

The attack sits inside a documented campaign. Health-ISAC warned the sector on 4 August of ShinyHunters attacks on corporate SSO accounts. ReliaQuest published on 17 August that the group was registering help-desk impersonation domains under the .claims top-level domain, and was itself hit on 22 August, inside McKesson's window, through reliaquest.claims, registered that day. The threat-intelligence firm Flare later found 61 such domains for 48 organisations registered between 26 July and 31 August through a single registrar, most with a certificate issued within a day of registration. ThreatPaper checked the domain reported for McKesson, mckesson[.]claims, against registry RDAP and certificate-transparency logs on 11 September and found no record of it ever existing, while the same checks on reliaquest.claims return the full registration and certificate history.

The two figures in every headline need separating from what McKesson has said. "284 million" is the attacker's count of database rows, which the attacker itself told BleepingComputer is not a count of people; McKesson has confirmed no number. "Confirmed data breach" is accurate as to exfiltration and, since 8 September, as to the categories of data that may be involved; it is not confirmation of the vector, the applications, the volume or the record count. Twelve class actions were filed in the Northern District of Texas between 30 August and 3 September, the earliest two days after the 8-K, all resting on the attacker's claims as relayed by the press.

Verification of Claims

  1. Claim: McKesson discovered the incident on 25 August 2026 and it took place between 20 and 25 August. → Verified → Form 8-K, 28 August 2026 (discovery date). McKesson Notice of Data Breach, 8 September 2026: "Our investigation determined that the incident took place between August 20 and August 25, 2026."

  2. Claim: Data was exfiltrated. → Verified → McKesson customer notice, 28 August: "unauthorized access and exfiltration of data". Update, 29 August: "the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units."

  3. Claim: The attackers used voice phishing to compromise employees' Okta accounts, then accessed Salesforce and Snowflake. → Partially verified — attacker's account, circumstantially supported → ShinyHunters to BleepingComputer, 28 August. McKesson's 8 September notice describes the incident as "targeting employee corporate accounts" and its earlier notices refer to "third-party applications", both consistent with the claim without confirming it. The identical technique was confirmed by the victim in the ReliaQuest incident of 22 August.

  4. Claim: 284 million patient records were stolen. → Superseded by the source → CyberInsider, 28 August, headlined "284 million patient records"; other outlets wrote "284 million patients". ShinyHunters told BleepingComputer the same day that the figure is "a raw count of approximately 284 million data records, or lines, rather than a count of unique individuals" and that it "does not know how many unique people are in those records". McKesson has published no count.

  5. Claim: About 1 TB of data was taken between 21 and 25 August. → Unverified → ShinyHunters' claim. McKesson's window begins on 20 August, one day earlier, and McKesson has given no volume.

  6. Claim: The mckesson[.]claims domain was used in the attack. → Unverified → BleepingComputer, attributing it to "another source", not to the attacker. ThreatPaper query of the .claims registry via RDAP on 11 September 2026 returned "Object not found"; a certificate-transparency search for mckesson.claims and for any .claims name containing "mckesson" returned nothing. The same checks on reliaquest.claims return a registration dated 22 August 2026 and a Google Trust Services certificate the same day.

  7. Claim: A ransom of $55,236,150 was demanded with a 72-hour deadline. → Unverified → ShinyHunters to CyberInsider and BleepingComputer. McKesson has not acknowledged a demand. The 72-hour deadline matches the pattern Google documented for the UNC6240 extortion cluster in 2025.

  8. Claim: McKesson filed an 8-K disclosing a material cybersecurity incident. → Partially verified — form correct, characterisation wrong → The 8-K exists, but it was filed under Item 7.01 (Regulation FD Disclosure), not Item 1.05 (Material Cybersecurity Incidents), and states the company "has not determined that the incident is material". It is a voluntary disclosure, not a materiality filing.

  9. Claim: Protected health information and Social Security numbers were involved. → Partially verified → McKesson, 8 September: PHI "may have been impacted"; the categories listed include SSNs, card numbers and banking information, qualified as "may have included" and "will not be the same for every impacted individual". The attacker's list is broader and unconfirmed.

  10. Claim: McKesson notified law enforcement. → Verified as a statement → Notice of Data Breach, 8 September: "notified law enforcement". No agency has confirmed an investigation.

Timeline

Date Actor Event Source
26 July 2026 ShinyHunters (assessed) First .claims test domain registered; brand-impersonation registrations begin 27 July. Flare, 10 Sept 2026
4 August 2026 Health-ISAC Warns the sector of rising ShinyHunters identity attacks on SSO accounts (Okta, Entra, Google) leading to SaaS data theft. Health-ISAC
17 August 2026 ReliaQuest Publishes that ShinyHunters is registering company[.]claims domains to impersonate help desks and IT teams. BleepingComputer, 28 Aug
18 August 2026 Flare First batch of 24 alerts to sector ISACs about pre-positioned .claims domains. Flare
20 August 2026 ShinyHunters (claimed) Incident begins, per McKesson's investigation. McKesson notice, 8 Sept
21 August 2026 ShinyHunters (claimed) Exfiltration begins, per the attacker. BleepingComputer
22 August 2026 ShinyHunters reliaquest.claims registered 19:23 UTC; ReliaQuest employee vished the same day; one Okta dashboard session obtained. RDAP; Health-ISAC TLP:WHITE, 24 Aug
25 August 2026 McKesson Discovers the incident; activates IR; engages external experts; notifies law enforcement. Exfiltration ends, per the attacker, who sends a demand with a 72-hour deadline. 8-K; McKesson notices; BleepingComputer
28 August 2026 CyberInsider; McKesson CyberInsider reports the ShinyHunters claim. McKesson files the 8-K (Item 7.01) and posts a customer notice; warns of "intermittent service degradation". CyberInsider; SEC; McKesson
29 August 2026 McKesson Confirms exfiltration tied to Oncology & Multispecialty and Medical-Surgical customers; "reasonable assurance of no ongoing unauthorized activity". McKesson update
30 August 2026 Plaintiffs First class action, O'Connor v. McKesson, N.D. Tex. 3:26-cv-02929. CourtListener
31 August 2026 Plaintiffs; ShinyHunters (assessed) Six further suits filed in N.D. Tex. Last .claims registration in the Flare dataset. CourtListener; Flare
2–3 September 2026 Plaintiffs Five more suits; twelve in total by 3 September. CourtListener
8 September 2026 McKesson Substitute Notice of Data Breach: window 20–25 August; "targeting employee corporate accounts"; PHI, SSN, card and bank data may be involved; 24 months of IDX monitoring. McKesson
10 September 2026 Flare Publishes analysis of 61 .claims domains across 48 organisations. Flare

Attack Anatomy

What follows separates the attacker's account, the victim's account, and what the same campaign did to a victim that has described it in detail. McKesson has confirmed only the second column.

Stage ShinyHunters' account McKesson's account
Initial access Vishing of multiple employees "targeting employee corporate accounts"
Foothold Okta SSO accounts taken over not stated
Targets Salesforce (fully, incl. support cases); Snowflake "third-party applications"
Volume ~1 TB over 21–25 Aug; ~284M rows "certain data"; no figure
Extortion $55.2M, 72 hours, no reply not acknowledged

Stage 0: infrastructure

The .claims campaign is the best-documented part of this incident, and none of it comes from McKesson. Flare's passive-DNS and certificate analysis found 61 domains across 48 brands, all through one registrar, in 12 nameserver groups consistent with separate Cloudflare accounts, 57 of them with a TLS certificate issued on or within a day of registration, none with mail records. The control case is ReliaQuest: reliaquest.claims was registered at 19:23 UTC on 22 August, a Google Trust Services certificate for it and *.reliaquest.claims was logged the same day, the vishing call came that day, and the registry placed the domain on serverHold on 27 August.

For McKesson, that evidence is absent. The registry has no object for mckesson.claims and no certificate for any .claims name containing "mckesson" has been logged. Either the domain used was different from the one reported, or it was a subdomain or another TLD, or the report is wrong. ThreatPaper cannot tell which.

Stage 1: the call

Loading diagram...

Health-ISAC's TLP:WHITE report on the ReliaQuest incident of 22 August describes the mechanism the campaign uses: an attacker "posing as a named internal security staff member" contacts several employees "to create a sense of urgency" and directs them to "a typosquatted domain hosted behind a content delivery network (CDN) to mirror the organization's corporate SSO authentication portal". The portal runs a reverse-proxy phishing kit, so the credentials pass through to the real identity provider and the victim receives a genuine MFA push, which they approve. What the attacker holds is not a password but a live session, "initiated from an unmanaged, external device". At ReliaQuest that session showed only the application launch tiles and was caught. ShinyHunters' account of McKesson is the same sequence carried through: from the Okta dashboard into Salesforce and Snowflake.

This is a change in the group's Salesforce tradecraft, not a new tradecraft. Google's June 2025 report on UNC6040 described vishing calls that walked employees through authorising a rebranded Salesforce Data Loader as a connected app, using an eight-digit device code, with an Okta phishing panel hosted on the same infrastructure. The FBI's FLASH of 12 September 2025 described UNC6040 calling victims' call centres "posing as IT support employees". Taking over the SSO session directly, rather than a single connected app, reaches every application behind the identity provider at once, which is how Snowflake enters an incident that begins as a Salesforce technique.

Stage 2: the data

Salesforce and Snowflake are the two platforms named, and only by the attacker. Salesforce would hold customer support cases, which ShinyHunters specifically claims. Snowflake is a cloud data warehouse; a healthcare distributor's analytics layer would plausibly hold the patient-level tables from its oncology practice-management and medical-surgical businesses, which is what the 284 million rows are said to be. McKesson's statement that the data relates to customers of those two business units is consistent with that reading. ShinyHunters told BleepingComputer it "has not fully analyzed the stolen data".

Stage 3: extortion

ShinyHunters says it contacted McKesson on 25 August with a demand of $55,236,150 and a 72-hour deadline, and that McKesson did not respond. The 72-hour deadline is the group's standard, documented by Google for the UNC6240 extortion cluster. As of 11 September no data has been published, and no leak-site posting has been reported.

Threat Actor Profile

  • Name / Alias: ShinyHunters. Google tracks the 2025 Salesforce vishing intrusions as UNC6040 and the extortion follow-on as UNC6240, noting the latter "has consistently used the alias" ShinyHunters. Whether the McKesson operators are the same individuals as any earlier ShinyHunters activity is not established.
  • Attribution basis: Self-claim to CyberInsider and BleepingComputer, with data samples shown to CyberInsider. McKesson has not attributed the incident.
  • Motivation: Financial extortion. No encryption, no disruption beyond the "intermittent service degradation" McKesson reported on 28 August.
  • Campaign context: Health-ISAC characterises the current activity as "behaving less like a 'traditional ransomware crew' and more like an identity- and SaaS-access extortion operation". Other healthcare-technology victims named in the same wave by BleepingComputer: Medtronic, DentaQuest, iRhythm, One Medical, AdaptHealth. The .claims infrastructure also hit ReliaQuest on 22 August.
  • Prior operations by the same alias: Salesforce data-theft wave (2025, Google, Qantas, Allianz Life and others, per FBI FLASH); Instructure Canvas (May 2026); Aura (March 2026).
  • MITRE ATT&CK techniques (verified on attack.mitre.org, 11 September 2026; ATT&CK has renumbered several techniques this year):
    • T1583.001 Acquire Infrastructure: Domains (.claims registrations)
    • T1566.004 Phishing: Spearphishing Voice; T1598.004 Phishing for Information: Spearphishing Voice
    • T1684.001 Social Engineering: Impersonation (help desk / security staff)
    • T1557 Adversary-in-the-Middle (reverse-proxy SSO portal)
    • T1621 Multi-Factor Authentication Request Generation
    • T1078.004 Valid Accounts: Cloud Accounts
    • T1213 Data from Information Repositories (Salesforce); T1530 Data from Cloud Storage (Snowflake)
    • T1567 Exfiltration Over Web Service

Technical Indicators

# McKesson has published no indicators. Everything below is campaign-level,
# from Health-ISAC, Flare and ThreatPaper's own registry checks. Defanged.
reported_but_unconfirmed:
  domain: mckesson[.]claims        # BleepingComputer, "another source"; no RDAP object,
                                   # no CT certificate as of 2026-09-11
confirmed_campaign_infrastructure:
  domain: reliaquest[.]claims      # registered 2026-08-22 19:23 UTC; GTS cert same day;
                                   # serverHold 2026-08-27 (RDAP, crt.sh)
campaign_pattern:
  tld: .claims
  naming: <company-name-or-abbreviation>.claims
  registrar: single registrar across 61 domains (Flare; not named)
  nameservers: Cloudflare, 12 distinct account groups (Flare)
  tls: certificate issued within 1 day of registration (57 of 61)
  mx: none
  pretext: named internal security or IT staff; urgency; help-desk reset
  kit: reverse-proxy SSO lookalike behind CDN; MFA push relayed
ip_addresses: []                   # none published for this incident
file_hashes: []                    # none; no malware reported
reference_iocs: FBI FLASH 2025-09-12 (UNC6040/UNC6395) for 2025-era user agents and IPs

SEC. The 28 August 8-K was filed under Item 7.01, Regulation FD Disclosure, signed by Executive Vice President and Chief Legal Officer Michele Lau, and states that McKesson "has not determined that the incident is material". Item 1.05, the mandatory four-business-day disclosure for incidents determined to be material, has not been triggered. If McKesson later determines materiality, a further 8-K would be due within four business days of that determination.

HIPAA. McKesson describes itself in the 8 September notice as "a vendor to health care providers", which is business-associate language. The notice is a substitute notice under 45 CFR 164.404(d)(2), used when contact information for affected individuals is insufficient, and says McKesson "will work with our customers as appropriate to determine the most efficient means to notify affected individuals". Individual notification and the report to HHS Office for Civil Rights are due without unreasonable delay and within 60 days of discovery, that is, by 24 October 2026. No entry for McKesson appeared on the OCR breach portal as of 11 September. Because the covered entities are McKesson's provider customers, the eventual portal entries may be filed by them rather than by McKesson.

Litigation. Twelve putative class actions were filed in the Northern District of Texas, Dallas Division, between 30 August and 3 September 2026: O'Connor (3:26-cv-02929), Olszewski (02948), Garand (02951), Hall (02958), Polaniec (02959), Murchison (02963), Diehl (02970), Johnson (02995), Willahan (02996), Balderrama (03002), Burns (03008) and others. Causes pleaded include negligence, breach of implied contract and unjust enrichment. Hall names CoverMyMeds LLC, McKesson's prior-authorisation subsidiary, as a co-defendant, on the plaintiff's inference that his prescription data passed through it; the complaint itself concedes McKesson "has not confirmed" any affected application. Consolidation and appointment of interim lead counsel are the next procedural steps.

Law enforcement. McKesson states it notified law enforcement. No agency has commented.

Sector. Health-ISAC issued warnings on 4 August (general) and 24 August (ReliaQuest, TLP:WHITE). No CISA or HHS advisory specific to McKesson has been issued; the FBI's most recent FLASH on this actor's Salesforce activity is dated 12 September 2025.

Impact Assessment

  • ExfiltrationConfirmed. McKesson, 28 and 29 August.
  • Business unitsConfirmed. Oncology & Multispecialty; Medical-Surgical. Subset of customers.
  • Categories of dataReported by McKesson as possible. Identification data, health insurance, medical information including diagnoses and test results, billing including card and bank numbers, Social Security numbers. "Will not be the same for every impacted individual."
  • Number of individualsUnknown. McKesson: review "in its early stages". Attacker: 284 million rows, unique people unknown.
  • VolumeReported. ~1 TB (attacker).
  • VectorReported. Vishing, Okta, Salesforce, Snowflake (attacker); "employee corporate accounts", "third-party applications" (McKesson).
  • Operational impactConfirmed, limited. "Intermittent service degradation" on 28 August; distribution "remain[ed] operational" on 29 August.
  • RansomReported. $55,236,150 demanded; McKesson has not acknowledged it.
  • Financial materialityNot determined by McKesson as of 28 August.
  • Litigation exposureConfirmed. Twelve federal suits within four days.

Lessons and Defensive Recommendations

For identity and SOC teams

  • The credential is not the target; the session is. A reverse-proxy kit defeats push-based and OTP MFA because the victim completes a real login. Only phishing-resistant factors bound to the origin, FIDO2/WebAuthn or device-bound passkeys, stop this, and they must be enforced for the IdP itself, not just downstream apps.
  • Bind IdP sessions to managed devices. Health-ISAC's recommendation after ReliaQuest is exact: restrict SaaS, portals and APIs to devices "verified via client certificates, EDR health checks, or MDM profiles". A stolen session from an unmanaged device should reach nothing.
  • Alert on new sessions from a residential or VPN IP against an identity that just approved a push, and on first-time access to Snowflake or Salesforce bulk-export functions from any session under an hour old.
  • Monitor certificate-transparency logs for your brand under .claims and other novel TLDs. The campaign issued certificates within a day of registration for 57 of 61 domains, which makes CT a faster signal than newly-observed-domain feeds.

For data-platform owners

  • A warehouse that holds 284 million rows of patient data behind an SSO tile is one approved push away from being copied. Network policies on Snowflake, IP allowlisting, row-access policies and query-volume alerting exist for exactly this.
  • Support-case data in Salesforce is PHI when the customer is a clinic. Treat CRM exports with the same controls as the EHR.

For help desks and employees

  • The pretext is a named colleague from security or IT, with urgency. A call-back to a number from the directory, not from the caller, breaks every variant of this campaign. Institutionalise it.

For leadership and counsel

  • Item 7.01 buys time but not much. Twelve suits were filed before McKesson had said what was taken; the record that will matter is what the company knew and when. Substitute notice on day 14 with the full category list is defensible; the vector will have to be stated eventually.
  • Do not repeat the attacker's numbers. "284 million patients" was wrong within hours and is still in headlines two weeks later.

Sources

  1. McKesson Corporation. Form 8-K, Item 7.01. US Securities and Exchange Commission, 28 August 2026.
  2. McKesson Corporation. Notice of Data Breach. 8 September 2026. (Internet Archive, 10 September 2026)
  3. McKesson Corporation. Customer Cybersecurity Information Center, notices of 28 and 29 August 2026. (Internet Archive, 31 August 2026)
  4. Lawrence Abrams, BleepingComputer. "McKesson discloses breach after ShinyHunters claims patient data theft". 28 August 2026.
  5. CyberInsider. "ShinyHunters claims McKesson data breach exposing 284 million patient records". 28 August 2026, updated twice the same day.
  6. Health-ISAC. "Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare". 4 August 2026.
  7. Health-ISAC via American Hospital Association. "Cyber Incidents TLP WHITE: ShinyHunters-Linked Social Engineering and Identity-Targeting Campaign". 24 August 2026.
  8. Adrian Cheek, Flare. "Finding and Notifying a ShinyHunters Claims Impersonation Campaign Before It Activated: 61 Domains, 48 Brands". 10 September 2026.
  9. BleepingComputer. "ReliaQuest confirms failed data-theft attack after ShinyHunters breach". August 2026.
  10. Google Threat Intelligence Group. "The Cost of a Call: From Voice Phishing to Data Extortion". June 2025.
  11. Federal Bureau of Investigation. "Cyber Criminal Groups UNC6040 and UNC6395 Compromising Salesforce Instances for Data Theft and Extortion". FLASH, 12 September 2025.
  12. CourtListener. Hall v. McKesson Corporation and CoverMyMeds LLC, N.D. Tex. 3:26-cv-02958, complaint. 31 August 2026.
  13. CourtListener. O'Connor v. McKesson Corporation, N.D. Tex. 3:26-cv-02929. 30 August 2026.
  14. HIPAA Journal. "ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson". August 2026.
  15. US Department of Health and Human Services. Breach Portal. Checked 11 September 2026.
  16. MITRE ATT&CK. T1684.001; T1566.004; T1557; T1621; T1078.004. Accessed 11 September 2026.
Original Incident Report →

Related Research

Between mid-2025 and August 2026, a cybercriminal collective operating primarily under the ShinyHunters brand—alongside associated activity clusters tracked as UNC6040, UNC6240, UNC6395, UNC6661, and...

Data BreachSupply Chain Attack

A financially motivated threat actor (UNC5537) compromised Snowflake customer instances across 165+ organizations by credential stuffing against accounts lacking MFA, exfiltrating terabytes of sensitive data, and conducting mass extortion — the largest cloud data warehouse compromise to date.

Data BreachExtortion & Blackmail

Three men who worked in incident response ran BlackCat attacks. One of them was simultaneously negotiating on behalf of ransomware victims — and passing the attackers his own clients' insurance limits.

RansomwareInsider ThreatExtortion & Blackmail