Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-09-01 ยท updated: 2026-09-01 ยท tags: [incident, shinyhunters, mckesson, healthcare, data-extortion, vishing, snowflake, salesforce] ยท confidence: medium ยท severity: critical ยท affected_sectors: [Healthcare] ยท au_impact: false

ShinyHunters Demands $55.2M From McKesson After 1 TB Data-Theft Claim

Summary

ShinyHunters claimed a $55,236,150 ransom demand against pharmaceutical distributor McKesson after exfiltrating roughly 1 TB of data between 21 and 25 August 2026. McKesson did not answer or negotiate the demand.

Details

The extortion group told BleepingComputer that vishing against multiple employees compromised Okta single sign-on accounts, which were then used to reach McKesson's Salesforce and Snowflake environments. ShinyHunters claimed the Snowflake haul holds approximately 284 million patient-related raw data records โ€” a line count, not a unique-individual figure โ€” spanning names, addresses, dates of birth, Social Security numbers, patient IDs, Medicaid and medical record numbers, medication/allergy information, diagnoses and appointment data.

ReliaQuest independently tied the campaign to ShinyHunters' documented pattern of registering .claims domains (here mckesson[.]claims) to impersonate IT help desks. McKesson disclosed the incident on 28 August and detected it on 25 August, has not confirmed what was stolen, and has not determined materiality.

Assessment

The McKesson incident extends ShinyHunters' 2026 healthcare sweep (Medtronic, DentaQuest, iRhythm, OneMedical, AdaptHealth, Baxter, Boston Scientific). The vishing-to-Okta-to-SaaS access chain is a repeatable initial-access pattern for the group, and the .claims-domain tradecraft is now a named indicator. The 284-million-record figure should be read as raw rows rather than affected individuals until McKesson's investigation settles the unique-person count.