Close Menu
    Facebook X (Twitter) Instagram
    Friday, September 18
    • Home
    • About Us
    • Contact Us
    • Submit Your Story
    • Terms of Use
    • Privacy Policy
    Facebook X (Twitter) Instagram
    Fortune Herald
    • Business
    • Finance
    • Politics
    • Lifestyle
    • Technology
    • Property
    • Business Guides
      • Guide To Writing a Business Plan UK
      • Guide to Writing a Marketing Campaign Plan
      • Guide to PR Tips for Small Business
      • Guide to Networking Ideas for Small Business
      • Guide to Bounce Rate Google Analyitics
    Fortune Herald
    Home»Business»McKesson Data Breach Exposes Millions of Patient Records as ShinyHunters Demand $55M Ransom
    McKesson data breach
    Business

    McKesson Data Breach Exposes Millions of Patient Records as ShinyHunters Demand $55M Ransom

    Funke AdeyemiBy Funke Adeyemi18/09/2026No Comments4 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    The McKesson data breach that came to light last week has widened considerably in scope: the ShinyHunters hacking group claims to have lifted approximately 284 million rows of patient and employee data from the Texas-based pharmaceutical giant’s cloud environments, and issued a ransom demand of $55,236,150 to keep it from going public.

    McKesson confirmed the intrusion in a statement on its website. Francisco Fraga, the company’s chief technology officer, told customers the stolen data relates to its oncology, multispecialty, and medical-surgical units. McKesson is one of the largest distributors of pharmaceuticals, medical supplies, and healthcare technology in the United States, supplying hospitals and healthcare providers across the country and, in doing so, processing large volumes of sensitive patient records.

    Five Days Inside McKesson’s Cloud

    According to McKesson’s official breach notice, attackers were inside the company’s systems between 20 and 25 August 2026. ShinyHunters told TechCrunch they used phishing and social engineering to trick employees into granting access, but a more precise picture has emerged: the group reportedly gained initial entry through voice phishing, or vishing, calls that persuaded staff to surrender their Okta single sign-on credentials. From there, the attackers moved into McKesson’s Salesforce and Snowflake cloud environments, exfiltrating data over four days between 21 and 25 August.

    ShinyHunters say the haul amounts to roughly one terabyte of data. The 284 million figure refers to rows of records, not necessarily unique individuals: a single patient can generate multiple records across appointments, prescriptions, and insurance claims. Even so, the categories of data taken are broad. The hackers say they seized names, addresses, and Social Security numbers alongside protected health information, including diagnoses, medications, allergies, and patient notes. McKesson employees’ home addresses were also among the files taken.

    TechCrunch verified a small subset of the sample data ShinyHunters provided against public records. The stolen files have not yet been publicly released.

    Ransom Deadline Passed Without Response

    ShinyHunters made contact with McKesson on 25 August 2026, presenting the $55,236,150 demand alongside a 72-hour deadline. According to reporting by Tech-Insider, the deadline passed around 28 August with no public confirmation of payment or further negotiation. McKesson did not respond to a request for comment on the ransom demand.

    On 25 August, McKesson filed a Form 8-K with the Securities and Exchange Commission (SEC), disclosing that it had discovered the incident that day and had activated its incident response protocols, engaged external cybersecurity experts, and notified law enforcement. As of the filing date, the company said it had not determined that the incident is material or that it has had, or is reasonably likely to have, any material impact on its financial condition or results of operations.

    McKesson reported the breach publicly on 28 August 2026 and is offering complimentary credit monitoring and identity protection services to individuals who believe their data was taken. A dedicated information line is available at (855) 760-5202, open 9am to 9pm ET, according to the company’s cybersecurity notice page.

    Legal and Regulatory Pressure Already Building

    The legal fallout arrived quickly. On 30 August 2026, a McKesson customer, Deneice O’Connor, filed a lawsuit in the U.S. District Court for the Northern District of Texas, making her case one of the first to target the company over the incident.

    McKesson was already navigating regulatory scrutiny before this breach. In March 2025, the U.S. Department of Justice served a Civil Investigative Demand under the False Claims Act on NDCHealth Corporation, a McKesson subsidiary, seeking documents related to cybersecurity requirements in federal government contracts. That inquiry, disclosed in a McKesson quarterly filing with the SEC, adds a layer of federal scrutiny to a company now dealing with one of the larger healthcare data breaches in recent memory.

    McKesson joins a lengthening list of healthcare companies hit in recent months. Boston Scientific suffered a cyberattack that knocked much of its network offline. Stryker saw hackers abuse internal tools to remotely wipe thousands of employee devices. Abbott Laboratories and Medtronic have both experienced attacks, while electronic patient records provider CareCloud and health technology company TriZetto each reported breaches affecting more than 3 million patients. ShinyHunters has also claimed credit for breaches at Amazon-owned OneMedical and dental insurer DentaQuest.

    Whether ShinyHunters moves to publish the McKesson files now that their deadline has passed is the immediate question. The group has done so before. If the data surfaces on criminal forums, the company’s materiality assessment in that August 8-K will face its first serious test.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Funke Adeyemi

    Funke Adeyemi spent a decade in corporate banking and fintech before moving to business journalism. She started in trade finance at a major UK bank, moved to a payments company scaling into African markets, and spent her last role leading partnerships at a cross-border remittance platform. She writes about business strategy, fintech, digital banking, and the corporate news that moves markets. She is interested in how companies actually make money rather than how they describe making money in investor presentations. Funke lives in South London. She reads earnings calls the way other people listen to podcasts, and finds them about as reliable.

    Related Posts

    AI and Zero-Day Exploits: The Threat to Government Hacking Power

    18/09/2026

    US Drone and Robot Restrictions Reshape a Fracturing Global Market

    17/09/2026

    Liux Big Microcar Bets on Biocomposite Bodies to Beat Chinese Rivals

    17/09/2026
    Leave A Reply Cancel Reply

    Fortune Herald Logo

    Connect with us

    FortuneHerald Logo

    Home   About Us   Contact Us   Submit Your Story   Terms of Use   Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.