McKesson Breach: ShinyHunters Claims 284M Patient Records
McKesson confirmed unauthorized access to third-party apps; ShinyHunters claims 284 million patient records stolen from the healthcare and pharma distribution giant.

McKesson confirmed unauthorized access to third-party applications and data theft. ShinyHunters claims 284 million patient records. McKesson has not confirmed that volume. Treat the ShinyHunters figure as unconfirmed.
Confirmed
- Unauthorized access to third-party applications: confirmed by McKesson.
- Data exfiltrated: confirmed.
- Volume and scope: not confirmed.
The “third-party applications” framing means the initial access point was a vendor system, not McKesson’s core infrastructure. This vector repeated at SickKids in August.
ShinyHunters’ Claim
284 million patient records. ShinyHunters has accurate prior disclosures at scale (AT&T 2024, Ticketmaster 2024).
Confidence: unconfirmed. Do not treat it as settled.
What to Watch
McKesson regulatory filings will clarify scope: SEC 8-K if material, HHS OCR notification if protected health information is confirmed.
ShinyHunters typically operates on a payment deadline before public release.
ATF confirmed a separate major ransomware incident this week. Clop targeted GE and Philips in August. Third-party access paths remain the consistent vector.
If your organization shares data with McKesson or its service partners, identify which third-party applications are in scope for this incident before McKesson names them publicly.
Found this useful? Share it.


