Extortion Group ShinyHunters Claims Breach of Healthcare Giant McKesson
Hackers allege the theft of millions of patient records from McKesson's Snowflake and Salesforce cloud environments following a social engineering attack.

Extortion outfit ShinyHunters has taken responsibility for a cyberattack targeting Texas-based pharmaceutical and medical supply distributor McKesson, marking the latest high-profile data security breach to hit the American healthcare sector.
McKesson acknowledged the security incident in a public statement released on its website on Friday, revealing that unauthorized parties breached several of its cloud-hosted accounts earlier in the week and exfiltrated files. In an advisory distributed to clients, Chief Technology Officer Francisco Fraga specified that the compromised information involves the distributor's oncology & multispecialty as well as its medical-surgical operational divisions. The company warned customers to expect intermittent operational disruptions as a result of the breach.
In statements provided to TechCrunch, members of the ShinyHunters collective indicated that they gained access to McKesson's internal systems by tricking staff members through social engineering and phishing schemes. The group stated that it extracted millions of rows of records stored within McKesson's cloud infrastructure, specifically targeting databases hosted on Snowflake and Salesforce platforms.
The exfiltrated repository contains extensive personal and protected health information, according to the threat actors. The exposed data reportedly encompasses patient names, residential addresses, Social Security numbers, medical diagnoses, prescribed pharmaceuticals, allergy records, and clinical notes. Additionally, the stolen files contained internal corporate information, including home addresses belonging to McKesson employees.
The extortion group has demanded a $55 million ransom payment from McKesson to prevent the public release of the stolen records, according to reporting by cybersecurity outlet Bleeping Computer. Representatives for McKesson did not respond to requests for comment regarding the ransom demand or the extent of the compromised systems.
TechCrunch reported that it inspected sample files and screenshots supplied by ShinyHunters, confirming the authenticity of a portion of the record set against public data. ShinyHunters has previously claimed responsibility for intrusions at other health organizations, including Amazon-owned primary care provider OneMedical and dental insurer DentaQuest.
The incident underscores a persistent wave of cyber intrusions disrupting medical technology providers and healthcare infrastructure. Medical device manufacturers including Boston Scientific, Stryker, Abbott Laboratories, and Medtronic have all experienced network attacks in recent months. Meanwhile, digital records vendors such as CareCloud and health technology firm TriZetto have each reported breaches compromising more than 3 million patient records.
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



