McKesson, one of the largest healthcare and pharmaceutical distributors in the US, disclosed a cybersecurity incident this week after the extortion group ShinyHunters claimed to have stolen a large volume of patient and employee data. McKesson's own SEC filing says it discovered the incident on 25 August 2026 and is still in the early stages of investigating; the company has not confirmed what data was taken or how much. ShinyHunters, in claims reported by multiple outlets, says it accessed roughly 284 million records — including patient names, dates of birth, Social Security numbers, patient and Medicaid IDs, medical record numbers, medication and diagnosis details, plus staff and physician data — and demanded over $55 million with a 72-hour deadline, which McKesson reportedly did not pay. Those figures come from the attacker, not from McKesson, and should be read as a claim rather than a confirmed fact until the company's own investigation concludes.
What is better established is the entry point. According to the reporting, attackers ran a voice-phishing (vishing) campaign against McKesson staff, using look-alike domains to pose as internal IT support and talk employees into handing over credentials or approving a login. That got them into the company's Okta single sign-on, which in turn opened access to Salesforce and Snowflake environments — the exact pattern behind a wave of high-profile breaches over the past two years, where one convincing phone call bypasses a company's entire password and MFA layer at once.
What this means for your business
- Vishing beats email phishing because it targets a person's judgment in real time, not a link they can hover over — train staff, especially anyone with helpdesk or IT-support access, to verify a caller's identity through a separate channel before resetting a password or approving an SSO prompt, no matter how urgent the call sounds.
- If your business uses single sign-on, one compromised SSO login can cascade into every connected app — check that your SSO provider requires phishing-resistant MFA (hardware keys or number-matching) for admin and helpdesk roles, not just a push notification anyone can approve under pressure.
- McKesson is a supplier to pharmacies, clinics, and hospitals well beyond its own walls — if a vendor you depend on handles your customer or patient data, ask what their own vishing and SSO-hardening posture looks like, since their breach becomes your notification letter.
- A three-business-day gap between discovery (25 Aug) and public disclosure (28 Aug) is fast by industry standards — if your business collects any personal data, know in advance who makes the call on when and how you'd notify customers, rather than figuring it out mid-incident.
The headline number here — 284 million records — is still an attacker's claim, not a confirmed fact. The confirmed part is the mechanism: a phone call convincing enough to walk past single sign-on, which is a risk every business with SSO and cloud SaaS tools carries, not just a distributor McKesson's size.