McKesson Confirms a Breach; ShinyHunters Claims 284 Million Rows, Not Patients
McKesson has confirmed an incident and almost nothing else. The 284 million figure is ShinyHunters' claim, it counts database rows rather than people, and this same group's numbers were cut roughly in half the last time anyone checked them.
McKesson has confirmed a cybersecurity incident detected on August 25, 2026, and very little else. Every larger number attached to this story, including the 284 million records now in most headlines, comes from ShinyHunters. The company has not confirmed a record count, a data category, an attack path, or a ransom demand.
That gap is the story. McKesson is one of the largest US distributors of pharmaceuticals and medical supplies to pharmacies, hospitals and clinics, so a serious breach there is consequential by definition. But the figure driving the coverage is an extortion group's own listing, and there is a specific, documented reason to treat this particular group's numbers as an opening bid rather than a measurement.
What Has McKesson Actually Confirmed?
Four things, all of them narrow. In a Form 8-K filed with the US Securities and Exchange Commission, McKesson disclosed an incident involving, in the filing's words, "unauthorized access to certain third-party applications and the exfiltration of certain data," as reported by Healthcare IT News and BleepingComputer. The filing puts detection at August 25, 2026, and the company announced it on August 28.
The filing also says the "investigation of the incident is in its early stages," and that McKesson has not determined the incident to be material or reasonably likely to have a material impact on its financial condition or results. Reporting on the filing identifies the affected units as McKesson's Oncology & Multispecialty and Medical-Surgical businesses, which is a meaningful limit: it is a subset of the company, not the whole of it.
Note what is absent. No number of individuals. No list of data types. No mention of how the attacker got in. Whether the eventual confirmed figure lands anywhere near 284 million is, right now, unknown to everyone outside the investigation.
What Is ShinyHunters Claiming?
ShinyHunters claims 284 million records and a specific route in, none of which McKesson has corroborated. The group added McKesson to its leak site and told BleepingComputer that it used voice phishing against multiple employees to compromise Okta single sign-on accounts, then reached McKesson's Salesforce and Snowflake environments and pulled roughly a terabyte of data over four days. It says it contacted the company after finishing on August 25, demanded $55,236,150 with a 72-hour deadline, and got no response.
The claimed data categories are wide: names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information and physician information. Every item on that list is the attacker's assertion.
|
● Confirmed Versus Claimed
A ledger of who is the source of each statement in circulation about this breach.
|
|
Confirmed by McKesson (SEC Form 8-K)
An incident occurred. Detected August 25, 2026. Unauthorized access to certain third-party applications and exfiltration of certain data. Oncology & Multispecialty and Medical-Surgical units. Investigation in its early stages. Not determined to be material.
|
|
Claimed by ShinyHunters only
284 million records. Approximately 1TB over four days. Vishing → Okta SSO → Salesforce and Snowflake. A $55,236,150 demand with a 72-hour deadline. Every data category in circulation, including Social Security and Medicaid numbers.
|
|
The precedent worth remembering
Carhartt, August 2026: Have I Been Pwned found 12.9 million real email addresses after excluding close to 12 million synthetic, test and non-human entries from the same group’s dump. Roughly half the claim.
|
|
Unknown to everyone outside the investigation
How many people are actually affected.
|
|
Sources: McKesson Form 8-K as reported by Healthcare IT News and BleepingComputer; ShinyHunters claims via BleepingComputer; Carhartt figures via Have I Been Pwned and BleepingComputer, August 2026. Ledger: The CyberSignal.
|
Why Treat the Number as an Opening Bid?
Because the last time anyone independently counted this group's data, the real figure came in at roughly half the claim. On August 27 we covered the Carhartt case in our weekly security roundup: Have I Been Pwned's analysis of the leaked Carhartt set identified 12.9 million unique email addresses likely belonging to real people, after excluding close to 12 million synthetic, test, disposable and non-human addresses that had been mixed into the dump. Troy Hunt's write-up flagged the tells, including customers listed in improbable places such as Benin and Montenegro and a cluster of birth dates in the early 1900s.
Then there is the arithmetic problem sitting inside the word "records." Reporting on the McKesson listing is explicit that the 284 million figure refers to database rows, not unique patients. A denormalised export, one row per prescription, per appointment, per claim line, produces many rows per person. Almost every headline in circulation says "284 million patient records" and lets the reader hear "284 million patients." Those are different statements, and the difference here is likely to be large.
Our assessment, offered as assessment and not as reporting: the eventual confirmed number will be materially lower than 284 million individuals, and possibly by an order of magnitude. We have no inside knowledge. That view rests entirely on the row-versus-person distinction and on this actor's demonstrated record of inflated counts. We will correct it here if McKesson's confirmed figure says otherwise.
The Attack Path Matters More Than the Number
The route ShinyHunters describes involves no malware, no CVE and no perimeter breach, which is exactly why it keeps working. Vishing to compromise SSO accounts, then straight into the SaaS platforms that hold the data. We covered the same playbook in Charter/Spectrum's confirmed 42 million records, and Microsoft's own mapping of three Salesforce attack paths attributed to this group covers the same ground. Treat the path as the reusable part of this story.
What a security team running that stack should do:
- Put phishing-resistant MFA on the identity provider. FIDO2 or passkeys on the IdP is the control that breaks this chain. More email filtering does not, because the initial contact is a phone call. Our explainer on multi-factor authentication covers why the factor type is the whole argument.
- Treat "the help desk can restore access by voice" as a critical-severity design flaw. Require out-of-band verification for every MFA reset and enrolment. Vishing against SSO works because a human approves something.
- Audit what your SaaS platforms actually hold. Salesforce and Snowflake accumulate far more regulated data than most teams assume. Ask what a compromised sales or analytics integration could reach today, then put bulk-export and query-volume alerting on those platforms. That is the detection that fires in this scenario.
- Rehearse mass session revocation. A compromised IdP session keeps granting downstream SaaS access until it is revoked, not until the password is changed. Know how long a full revocation takes before you need it.
- Do not scope your response off an extortion group's row count. Notification volume, credit-monitoring spend and board briefings should wait for the notifying entity's confirmed figure. The rules that govern that timing are in our guide to data breach notification laws, and the mechanics of how an incident becomes a notification are in our explainer on what a data breach is.
What Is Still Open
Nearly everything a patient would want to know. McKesson has not confirmed the record count or the data categories. No regulator has commented. No notification letters have been reported. The company's own filing says the investigation is in its early stages, which is a genuine statement about its knowledge and not a dodge, eight days in.
We will update this piece when McKesson confirms a figure. Until then, the honest summary is short: a large healthcare distributor was breached, an extortion group says it took a great deal, and nobody outside the investigation knows how many people that means.
Primary Documents
- McKesson discloses breach after ShinyHunters claims patient data theft (BleepingComputer, which spoke to the group and is the origin of the actor's claims)
- McKesson investigating cybersecurity incident involving 'exfiltration of certain data' (Healthcare IT News, on the Form 8-K language)
- ShinyHunters claims it stole 284 million patient records from McKesson (Help Net Security, source for the rows-not-patients qualifier)
- ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson (HIPAA Journal)
- Have I Been Pwned: Carhartt Data Breach (the 12.9 million confirmed figure behind the precedent above)