mckesson data breach

The McKesson data breach shows how vulnerable the human connection is. Unlike complex hacking intrusions that rely on sophisticated programming through back channels, ShinyHunters uses social engineering to trick people into giving away security information. McKesson is the most recent and the largest healthcare victim so far this year.

Just weeks after we covered ShinyHunters’ attack on Baxter International, the extortion group has claimed a far larger healthcare target: McKesson, one of the country’s largest pharmaceutical distributors and healthcare technology companies. The scale of this incident, both in the volume of data claimed and the sensitivity of what’s been confirmed exposed, makes it the group’s most significant healthcare breach yet.

McKesson Was Surprised in August

McKesson reported the cybersecurity incident in a Form 8-K filing with the SEC on August 25th, confirming “a cybersecurity incident affecting its information systems.” The Securities and Exchange Commission requires companies to file a Form 8-K to announce major events that shareholders should know about.

In a separate public statement on August 28, the company said its investigation found that hackers accessed “certain third-party applications” and that the exposed data was linked to customers in its Oncology & Multispecialty and Medical-Surgical business units. McKesson added that it had “reasonable assurance of no ongoing unauthorized activity” and that its distribution centers remained operational.

ShinyHunters claimed responsibility and told reporters it stole about 284 million records over four days, demanding $55.2 million to keep the data from being published. That demand apparently went unmet.

On September 8, McKesson issued a more detailed breach notice confirming that the exposed protected health information (PHI) included names, addresses, phone numbers, email addresses, patient IDs, and dates of birth, along with additional information depending on the individual.

Two days later, security researcher Troy Hunt of Have I Been Pwned independently analyzed the published dataset and confirmed it contained 6.4 million unique email addresses tied to patients, staff, healthcare provider contacts, and marketing campaign recipients. Hunt’s analysis, along with reporting from The Register, also found that the stolen data included appointment dates and clinical notes, and in some cases specifics such as the location of a patient’s cancer, reflecting McKesson’s role supporting roughly 3,300 oncology providers through its specialty health business.

As with many of ShinyHunters’ claimed totals, the 284 million figure almost certainly does not represent 284 million unique patients; extortion groups’ large claimed record counts typically include duplicate rows, system logs, and other non-patient data mixed with genuine PHI. Even the confirmed 6.4 million affected email addresses alone make this substantially larger than the Baxter incident we covered last month.

The Same Playbook, Bigger Target

The attack path will sound familiar to anyone following ShinyHunters’ recent healthcare campaign. According to the group, attackers used voice phishing (vishing) to deceive McKesson employees into handing over the access needed to reach the company’s systems, rather than directly exploiting a software vulnerability. They then used that access to reach third-party applications connected to McKesson’s environment.

We’ve tracked this exact pattern across the group’s healthcare targets this year: DentaQuest, Amazon One Medical, Medtronic, NAIC, AdaptHealth, Abbott Laboratories, Exact Sciences, and Baxter International. In nearly every case, the initial compromise stems from social engineering targeting employees or contractors rather than a direct technical exploit, followed by the group’s now-standard pay-or-leak extortion model. McKesson fits that pattern precisely, though at a larger scale than most of the healthcare organizations that came before it.

In a weird twist, ShinyHunters just attacked a big ransomware competitor: Bleeping Computer reported that over the weekend, the group hacked into Clop’s data leak site. They defaced the site and allegedly stole data. The dispute appears to stem from competition over the 2025 Oracle E-Business Suite data hack.

Why McKesson Stands Out

A few factors make the McKesson incident more consequential than most of ShinyHunters’ other healthcare targets this year:

The extortion demand was unusually large. A reported $55.2 million demand is well above what’s been publicly reported for other ShinyHunters healthcare targets, reflecting both McKesson’s size and the sensitivity of what was taken.

The exposed data includes highly sensitive clinical detail. Cancer diagnosis and location information, tied to specific patients through McKesson’s oncology support business, goes well beyond the contact information and general PHI categories exposed in many breaches. That kind of data carries outsized risk for the patients affected and outsized liability exposure for McKesson and the oncology practices it serves.

McKesson’s role in the healthcare supply chain is enormous. As one of the country’s largest pharmaceutical distributors, McKesson doesn’t just hold its own data; it sits at the center of a vast network of provider relationships. A breach here would have ripple effects across the thousands of practices and health systems that rely on McKesson’s systems and services.

What This Means for Covered Entities and Business Associates

If your organization works with McKesson, whether as an oncology provider, a multispecialty or medical-surgical customer, or in any capacity involving the affected business units, you should be taking action now.

Determine whether your organization or patients were affected. McKesson’s breach notice and public statements are the authoritative source; confirm directly with McKesson rather than relying on third-party reporting.

Review your own breach notification obligations. If McKesson is a business associate to your organization, its breach may trigger your own HIPAA notification requirements to affected patients, even though the underlying incident occurred on McKesson’s systems.

Watch for downstream phishing risk. With millions of email addresses now circulating, expect a wave of follow-on phishing attempts using this data as a hook, targeting both affected patients and staff at organizations connected to McKesson.

Revisit vendor open authorization (OAuth) and third-party application access. As with Baxter, Medtronic, and other ShinyHunter targets, the initial foothold came through a connected third-party application rather than McKesson’s core systems. Review which third-party apps have standing access to your environment to catch this pattern.

Review and bolster your cybersecurity training. Add vishing to the list of ways hackers access data. Many employees have been trained on phishing, but fewer know about sophisticated voice phishing. Callers can impersonate anyone, including known vendors and others within their own organization.

ShinyHunters shows no sign of slowing its healthcare campaign, and McKesson’s scale suggests the group is increasingly willing to target the industry’s largest players, not just smaller providers and specialty vendors.

The HIPAA E-Tool® will continue to track the McKesson incident as the investigation unfolds, along with the broader campaign ShinyHunters wages against the healthcare sector.

Free HIPAA Checklist
What best describes you?