Sunday, August 30, 2026
๐Ÿ›ก๏ธ
Adaptive Perspectives, 7-day Insights
Healthcare IT

McKesson Breach: 284 Million Rows, Unknown Number of Patients

McKesson confirmed data exfiltration after ShinyHunters claimed 284 million patient records โ€” a figure the group itself says counts rows, not people.

McKesson Breach: 284 Million Rows, Unknown Number of Patients
Image via OpenAI gpt-image-2

Note: This post was written by Kimi K3. The following is a synthesis of McKesson’s SEC filing and customer notice, and reporting from BleepingComputer and CyberInsider.

McKesson confirmed Friday that it is investigating a cybersecurity incident involving unauthorized access to third-party applications and the exfiltration of data โ€” discovered August 25, disclosed in an SEC filing three days later. The confirmation came after the ShinyHunters extortion group claimed it had stolen 284 million patient records, a figure widely reported as “284 million patients” before the group itself walked it back.

That walk-back matters: 284 million is a raw count of database records, not people. How many patients are actually affected, no one knows โ€” including, by its own account, the group that did the stealing.

What McKesson has confirmed

The disclosure runs through an 8-K filed under Item 7.01 โ€” Regulation FD โ€” not Item 1.05, the material-incident provision. “The company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact,” the filing reads. Medtronic made the same filing choice in April; Boston Scientific used its equivalent last week. Going public fast while deferring materiality has become the industry’s default.

A customer notice adds the operational detail: the incident involved third-party applications, and customers may see “intermittent service degradation” believed related to the attack. McKesson says it is not proactively disconnecting systems within its own environment. It has not said which applications were compromised, how the attackers got in, or what data was taken.

That “third-party applications” phrasing is worth watching. If the intrusion ran through SaaS platforms on stolen single sign-on credentials โ€” which is what the attackers claim โ€” the phrase is technically accurate and places the boundary in the most favorable spot available: someone else’s software.

What ShinyHunters says it did

The group’s account, given to BleepingComputer: voice-phishing calls against multiple McKesson employees captured their Okta single sign-on credentials, which opened the company’s Salesforce and Snowflake environments. It claims a full compromise of the Salesforce instance, support cases included, and a much larger haul from Snowflake โ€” the 284 million records. Exfiltration ran about a terabyte over four days, August 21 through 25. The ransom demand was $55,236,150, with a 72-hour deadline McKesson let pass without responding.

BleepingComputer separately learned the campaign used mckesson[.]claims โ€” matching a ShinyHunters pattern ReliaQuest recently documented: [company].claims domains registered to impersonate corporate help desks during the vishing calls. CyberInsider, which broke the story, reviewed data samples the group provided privately and found them consistent with the claimed data types.

None of this is verified by McKesson. But the technique โ€” vishing into the identity provider, then pivoting to SaaS data stores โ€” is the same playbook behind this year’s ADT, Canvas, and Medtronic incidents, and it exploits no software vulnerability at all. It exploits the help desk.

284 million rows is not 284 million patients

The clarification came from the group itself: it has not analyzed the haul deeply enough to know how many unique individuals are in it. Its estimate to CyberInsider was tens of millions of patients, exact number unknown.

For scale: 284 million people would be more than four of every five Americans, and half again the roughly 190 million affected by the Change Healthcare breach, the largest in U.S. healthcare history. The mechanics explain the gap. A pharmaceutical distributor’s systems record events, not patients: every prescription fill, shipment, invoice, and support case is a row, and one patient generates dozens. The dataset allegedly mixes in employee records, physician and clinic directories, and internal communications besides.

The group’s own campaign supplies the calibration. In April it claimed 9 million records from Medtronic; the eventual notification count was 3.8 million people. DentaQuest produced three different numbers โ€” 234 GB claimed, 15 million people notified, 2.6 million accounts validated in the data actually published (covered here in July). The legally meaningful figure is the one that lands on the HHS Office for Civil Rights breach portal, and it has consistently arrived well below the extortion headline.

Serious at any corrected count

The correction is not exculpation. The data types ShinyHunters describes are among the most sensitive a healthcare company can hold: Social Security numbers, Medicaid numbers, and medical record numbers; medication, allergy, diagnosis, and appointment data; hospice and terminal-illness records, causes of death, autopsy details, and sexual orientation; predictive disease-risk scores, including cancer predictions tied to named patients. If even a fraction survives verification, this is grave at any row count.

The denominator is enormous either way. McKesson picks, packs, and ships one-third of U.S. pharmaceutical volume out of 26 distribution centers; it is a top-ten Fortune 500 company with $308.9 billion in 2024 revenue. Even the group’s own “tens of millions” would rank this among the largest healthcare breaches on record. The operational question is live too: service degradation at the company moving a third of the country’s medicine, two days after Boston Scientific’s order pipeline went down in an unrelated attack โ€” the healthcare supply chain absorbing two hits in one week.

What to watch

  • The OCR portal. The affected-individuals count that lands there โ€” weeks to months out, on Medtronic’s timeline โ€” is the number this story will be remembered by.
  • Materiality. An amended 8-K under Item 1.05 would mean McKesson now considers the incident financially significant. Class actions are likely being drafted already; Medtronic’s arrived within a week.
  • The leak site. Whether McKesson’s listing appears, disappears, or produces a published archive will say more about negotiations than any statement. Medtronic’s listing vanished without explanation; DentaQuest’s data was dumped when talks collapsed.
  • The scope claim. “Third-party applications” either holds or it doesn’t. McKesson’s investigation โ€” and the notification letters, if they come โ€” will settle it.

Sources