Executive Summary
On August 25, 2026, McKesson discovered a cybersecurity incident involving unauthorized access to third-party applications and subsequent data exfiltration. The extortion group ShinyHunters claimed responsibility, stating they used voice phishing (vishing) attacks to compromise employee credentials and access sensitive data. The attackers reportedly exfiltrated approximately 1TB of data over four days and demanded a $55,236,150 ransom. McKesson filed an official Form 8-K with the SEC on August 28, 2026, confirming the incident and ongoing investigation. As of the filing date, McKesson had not determined the incident to be material or to have had a material impact on its financial condition. The company has engaged cybersecurity experts and is providing updates at www.mckesson.com/cybersecurity. The breach is part of a broader trend of attacks targeting healthcare organizations, highlighting the sector’s vulnerability to social engineering and cloud account compromise.
Technical Information
The incident began with a targeted social engineering campaign by the ShinyHunters group, who used vishing (voice phishing) to impersonate McKesson’s help desk and IT teams. The attackers registered and used the domain mckesson[.]claims to lend credibility to their impersonation efforts, a tactic previously documented in similar campaigns. Through these vishing attacks, multiple McKesson employees were tricked into revealing their credentials for the company’s Okta single sign-on (SSO) system.
With valid Okta SSO credentials, the attackers gained access to McKesson’s Salesforce and Snowflake environments. Over a four-day period from August 21 to August 25, 2026, the attackers exfiltrated approximately 1TB of data. The compromised data, as claimed by ShinyHunters, includes personally identifiable information (PII) such as names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment and physician information, data related to deceased and terminally ill patients, prescriptions, medication shipments, invoices, employee information, Salesforce records, internal communications, and information on healthcare providers and clinics using McKesson’s services. It is important to note that these specific data types have not been independently confirmed by McKesson or third-party investigators as of the latest public disclosures.
The attackers issued a ransom demand of $55,236,150, giving McKesson 72 hours to respond. McKesson did not engage in negotiations. The company has since engaged leading cybersecurity experts to assist with the investigation and response.
The attack leveraged several well-documented tactics, techniques, and procedures (TTPs) associated with ShinyHunters. These include the use of vishing (MITRE ATT&CK T1598.003), domain impersonation for social engineering (T1566.003), credential theft and abuse of valid accounts (T1078), lateral movement within cloud environments, and large-scale data exfiltration (T1567.002). The use of the .claims top-level domain (TLD) for impersonation is consistent with previous ShinyHunters campaigns targeting the healthcare sector.
No specific malware or malicious code was reported in connection with this incident. The primary tools were social engineering, domain impersonation, and exploitation of cloud account credentials. The only technical indicator publicly associated with the attack is the domain mckesson[.]claims. No file hashes, IP addresses, or additional indicators have been disclosed in public reporting as of August 28, 2026.
The incident underscores the risks associated with cloud and SaaS platforms in the healthcare sector, particularly when social engineering is used to compromise privileged accounts. The attack also highlights the importance of robust multi-factor authentication (MFA), employee security awareness training, and vigilant monitoring of cloud access patterns.
Affected Versions & Timeline
The breach affected McKesson’s Okta SSO, Salesforce, and Snowflake environments. The attack window, as claimed by ShinyHunters, spanned from August 21 to August 25, 2026, during which approximately 1TB of data was exfiltrated. McKesson discovered the incident on August 25, 2026, and filed an official SEC Form 8-K on August 28, 2026. The investigation is ongoing, and McKesson has not yet determined the full scope of affected systems or data.
Threat Activity
ShinyHunters is a well-known extortion group active since at least 2020, specializing in data theft, extortion, and the sale of stolen data. The group has a documented history of targeting cloud and SaaS environments, often using social engineering to compromise credentials. In this incident, ShinyHunters used vishing and domain impersonation to gain initial access, then leveraged compromised Okta SSO credentials to move laterally and access sensitive data in Salesforce and Snowflake.
Recent campaigns by ShinyHunters have targeted other healthcare and health technology organizations, including Medtronic, DentaQuest, iRhythm, OneMedical, and AdaptHealth, using similar tactics. The group’s focus on the healthcare sector is driven by the high value of patient data and the sector’s reliance on cloud platforms. Health-ISAC has issued warnings about ShinyHunters’ tactics, emphasizing the need for heightened vigilance among healthcare organizations.
The attack on McKesson is consistent with ShinyHunters’ known TTPs, including the use of vishing, domain impersonation with .claims TLDs, and exploitation of cloud account credentials. The group’s activities are mapped to several MITRE ATT&CK techniques, including T1566.003 (Phishing: Spearphishing via Service), T1598.003 (Vishing), T1078 (Valid Accounts), T1530 (Data from Cloud Storage Object), T1213 (Data from Information Repositories), and T1567.002 (Exfiltration Over Web Service).
Mitigation & Workarounds
The following mitigation strategies are prioritized by severity:
Critical: Organizations should immediately review and strengthen multi-factor authentication (MFA) for all cloud and SaaS accounts, especially those integrated with Okta SSO. Security teams should conduct targeted phishing and vishing awareness training for all employees, with a focus on help desk and IT impersonation scenarios.
High: Monitor for suspicious access patterns in Okta, Salesforce, and Snowflake environments, including anomalous logins, data access, and large-scale data transfers. Review and restrict access permissions for sensitive data repositories, and ensure that least privilege principles are enforced.
Medium: Conduct regular audits of domain registrations that could be used for impersonation (e.g., .claims TLDs with your organization’s name) and implement domain monitoring services. Engage with threat intelligence providers to stay informed about emerging TTPs targeting your sector.
Low: Update incident response playbooks to include scenarios involving vishing and cloud account compromise. Ensure that all employees know how to report suspected phishing or vishing attempts.
Indicators of Compromise
The following caveat applies: Indicators of compromise are point-in-time and should be validated in your environment before enforcement. At the time of writing, the only publicly disclosed indicator associated with this incident is the domain mckesson[.]claims.
Type | Indicator | Reported (date) | Source
|
Domain | mckesson[.]claims | 2026-08-28 | https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/ |
No additional public indicators of compromise were available at the time of writing.
References
BleepingComputer, “McKesson discloses breach after ShinyHunters claims patient data theft,” August 28, 2026 https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/
StockTitan, “McKesson reports cybersecurity incident on Aug. 25 | MCK 8-K Filing,” August 28, 2026 https://www.stocktitan.net/sec-filings/MCK/8-k-mckesson-corp-reports-material-event-fcb03c61b0cf.html
About Rescana
Rescana provides a third-party risk management (TPRM) platform designed to help organizations identify, assess, and monitor cybersecurity risks in their vendor ecosystem. Our platform enables continuous monitoring of vendor security posture, supports incident response workflows, and facilitates evidence-based risk assessments for cloud and SaaS providers. For questions about this report or to discuss how our capabilities can support your risk management program, contact us at info@rescana.com.



