Skip to main content
Breach Signal

Breach report

Healthcare

McKesson

Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson

The ShinyHunters extortion group says it phished its way into McKesson's cloud accounts and stole millions of rows of patient data, including diagnoses and Social Security numbers, from the drug distribution giant's oncology and medical-surgical units.

Reported by TechCrunch

Records exposed

Undisclosed

Undisclosed (hackers claim millions of patient records)

When
2026
How they got in
Phishing and social engineering to access cloud-hosted accounts (Snowflake, Salesforce)
Sector
Healthcare

At the end of August 2026, McKesson, one of the largest pharmaceutical distributors and healthcare services companies in the United States, confirmed a data breach after hackers accessed cloud-hosted accounts and took sensitive information. A notice from the company's chief technology officer said the affected data related to its oncology and multispecialty business and its medical-surgical unit, which serve physician practices and cancer care providers. McKesson is one of the largest companies in the United States by revenue, and its businesses supply drugs and medical products to pharmacies, hospitals and physician practices nationwide.

The ShinyHunters extortion group claimed responsibility, telling TechCrunch it used phishing and social engineering to trick employees into granting access. The group said it pulled data from McKesson's Snowflake and Salesforce environments, and it shared samples and screenshots that TechCrunch partly verified against public records. ShinyHunters said it had taken millions of rows of patient data but did not know how many individuals were ultimately affected. BleepingComputer reported that the hackers demanded a ransom of about $55 million.

According to the hackers and the samples reviewed, the stolen information included patient names, addresses, Social Security numbers, diagnoses, medications, allergies and clinical notes, as well as home addresses of McKesson employees. McKesson said it continued to operate all lines of business and did not believe unauthorized activity was ongoing, though it warned of intermittent service degradation. The company declined to say how many people were affected or whether it would negotiate.

The incident is part of a surge of data theft attacks against healthcare and medical technology companies in 2026, following reported breaches at dental benefits administrator DentaQuest, claims processor TriZetto, and device makers including Medtronic and Stryker. ShinyHunters has repeatedly targeted cloud software platforms rather than exploiting software flaws, relying on convincing calls and messages to employees to obtain credentials or authorize malicious apps.

Because McKesson has not yet filed notification numbers with regulators, the full impact remains unclear. The case shows how clinical data increasingly lives in general-purpose cloud platforms, where access controls depend on employee vigilance and identity verification. For patients of affected practices, the combination of diagnoses and Social Security numbers creates lasting risks of fraud and targeted extortion.

More from the wire

More in Healthcare.

All 107 reports

Private AI for Life

Live your best life with Thinkspan: the all-in-one smart solution for organizing, securing, and accessing personal information. With Thinkspan, your life’s most important information stays protected and accessible.