THE TELL

A phone call, four days, and a terabyte of pharmacy records

McKesson, the giant that ships medicines to pharmacies across the US, says someone got into third-party apps it uses and pulled data out. The group claiming responsibility says it started with phone calls to employees.

On August 25, 2026, McKesson discovered that someone had been inside. The company filed a Form 8-K with the US Securities and Exchange Commission confirming unauthorized access to third-party applications and the theft of data. It said the investigation "remains in the early stages" and that it has not determined the incident is material or reasonably likely to have any material impact on its financial condition or results of operations.

The extortion group ShinyHunters told BleepingComputer it was behind the attack. Its version: vishing — voice phishing, meaning someone calls an employee and talks like the help desk until the employee hands over access. The group says that got them into multiple employees' Okta single sign-on accounts, the one login that opens everything else, and from there into the company's Salesforce and Snowflake environments. It claims it took about 1TB of data over four days, between August 21 and August 25.

What it means

McKesson doesn't sell you anything directly. It sits between drugmakers, pharmacies and clinics — medicines, supplies, technology, services. Which means your name can be in its systems without you ever having heard of it. That's the part worth sitting with: the companies holding the most sensitive facts about your health are often companies you've never chosen.

ShinyHunters claims the Snowflake data contains roughly 284 million records. That number has already been misread once. Earlier reporting said 284 million patients were exposed. The group itself clarified to BleepingComputer that it's a raw count of records — lines in a table — not unique people, and that it hasn't finished analyzing the data and doesn't know how many individuals are in there.

Nobody knows yet how many people this touches. Not us, not the company, not even the thieves.
Share this

What the group says is in there is the uncomfortable part: names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication and allergy information, illnesses, disabilities, appointment information and physician information. It also claims data on deceased and terminally ill patients, prescriptions and medication shipments. BleepingComputer has not independently verified any of it, and McKesson has not publicly said what was taken. The group says it demanded $55,236,150 with a 72-hour deadline and that McKesson did not respond or negotiate.

Who it matters to

Anyone who has filled a prescription at a US pharmacy — you never picked McKesson, McKesson just happens to be in the supply chain behind the counter. And anyone whose job includes answering the phone at work: help desks, support staff, junior employees with a company login. The way in here wasn't a clever exploit, it was a conversation. One source told BleepingComputer the attackers used a domain called mckesson[.]claims, matching a ShinyHunters campaign ReliaQuest documented, where the group registers company[.]claims domains to impersonate a target's own help desk and IT team. If you're 24 and the newest person on the team, you are the intended target of that call.

What's next

McKesson says its investigation is ongoing and that it will provide additional information as it develops a more complete understanding, with updates posted at www.mckesson.com/cybersecurity. Customers may see intermittent service degradation the company believes is related to the attack. No deadline, no date, no follow-up filing has been announced — the company has not said when it will say more, and neither has anyone else.

One detail to hold on to

The ransom demand wasn't a round number. It was $55,236,150 — priced to the dollar, as if someone had run a calculation. Then McKesson, according to the attackers, simply didn't reply. If refusing to pay becomes the norm, the data doesn't vanish. It just stops having a buyer.

Sources: Bleeping Computer, «McKesson discloses breach after ShinyHunters claims patient data theft», August 28, 2026; McKesson Form 8-K filing with the U.S. Securities and Exchange Commission and customer notice, as quoted therein.

Why we ran this8/10

У крупнейшего в США дистрибьютора лекарств украли около терабайта данных — по словам вымогателей, там номера соцстрахования, диагнозы, аллергии и рецепты, а выкуп в 55 млн долларов компания платить отказалась.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← A model needed a number it couldn't find…Next: The scammer gave her the password. That wa… →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X