McKesson, the distributor that supplies medicines and medical supplies to pharmacies, hospitals and physician practices across North America, has confirmed that intruders reached applications it uses and copied data out. The extortion crew claiming the attack, ShinyHunters, says the haul runs to roughly 284 million records.
That number is the criminals' figure, not the company's. The two accounts of this breach are very far apart.
McKesson says it discovered the incident on 25 August 2026 and that its investigation remains in the early stages. The company has confirmed unauthorized access to certain third-party applications and the exfiltration of certain data, and has tied that activity to a subset of customers within its Oncology and Multispecialty and its Medical-Surgical business units. It has not said what the data covers, how much of it there is, or which applications were involved. IntelFusions covered the company's initial disclosure and its SEC filing earlier this week.
A phone call, then the single sign-on keys
ShinyHunters claims it got in by calling McKesson staff and talking them into handing over access, a technique known as voice phishing, or vishing. From there, according to the group, it used compromised Okta single sign-on accounts, the central login that unlocks a company's other cloud services, to reach McKesson's Salesforce and Snowflake environments. It says it removed about 1 TB of data between 21 and 25 August.
None of that has been confirmed by McKesson, and it comes from the party with the strongest reason to exaggerate. It is still worth reading, because the route described involves no software exploit at all. It is an identity story: talk to a person, borrow their login, then walk into the platforms where the records actually sit. Malwarebytes published a summary of the claims and the company's response.
284 million records is not 284 million people
Record counts and people counts are different quantities, and extortion crews rarely distinguish between them. One patient can appear dozens of times across order lines, claims and shipment records, so a large row count can describe a much smaller population. Until McKesson finishes its review, the honest position is that the scale is unknown.
Why health data is worth more to a scammer
Identity details combined with healthcare details make impersonation easy. A criminal can pose as a pharmacy, an insurer, a medical provider, a debt collector or a patient-support service, and quote real information to make the approach look legitimate. The pressure tactics follow naturally: a prescription problem, an unpaid claim, a delivery issue, an appointment change, a request to verify insurance details. McKesson has not confirmed that any specific category of patient data was accessed.
Verify the caller on a channel you picked
Anyone who thinks they may be affected should follow McKesson's own advice as it is published, change any password reused elsewhere, and move to phishing-resistant two-factor authentication where possible. A FIDO2 hardware key, laptop or phone cannot be phished the way a one-time code can. Treat any inbound call, text or email claiming to come from a pharmacy, insurer or the company itself as suspect, and verify it through a number or address you looked up yourself.
For enterprises, the defensive lesson sits with the help desk rather than the firewall. If a voice on a call can get a password reset or an MFA re-enrollment, the identity provider is only as strong as that conversation.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.