The mckesson[.]claims domain was used in the attack
Assessment
BleepingComputer attributed this to "another source", not to ShinyHunters, which "declined to provide" the domain. On 11 September 2026 ThreatPaper queried the .claims registry through RDAP, which returned "Object not found", and searched certificate-transparency logs, which hold no certificate for mckesson.claims or for any .claims name containing "mckesson". The same two checks on reliaquest.claims return a registration on 22 August 2026, a certificate issued the same day, and a serverHold from 27 August. A deleted domain would normally still appear in RDAP for at least 30 days. Nothing found supports the claim; nothing found rules out a differently spelled domain.
Where this claim appeared
BleepingComputer · 2026-08-28
https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/What “Unverified” means
Widely repeated, but no supporting evidence was located. This is not a statement that the claim is false — it is a statement that nothing published supports it, which is a different and more common problem.
2 of 5 · rating scale
Assessed in
McKesson Data Breach: ShinyHunters, One Phone Call, and 284 Million Rows of Patient DataThink this assessment is wrong? Report an error.