Overview
- McKesson detected the incident on Aug. 25 and says unauthorized access to third‑party cloud applications led to confirmed exfiltration of data tied to customers in its Oncology & Multispecialty and Medical‑Surgical units.
- The extortion group ShinyHunters has claimed responsibility, told reporters it removed about 1 TB of data and asserted roughly 284 million database rows were taken while demanding about $55 million.
- McKesson says distribution and core services remain operational, it activated incident response protocols, engaged outside cybersecurity experts, and offered credit monitoring and identity protection to impacted individuals.
- Key technical details reported by researchers and the attackers say access began with social engineering (vishing) to steal Okta single‑sign‑on credentials and then moved into Salesforce and Snowflake environments.
- The company has not independently confirmed the full scope of records, specific data types, or any ransom payment and regulators and privacy rules, including potential HIPAA notification obligations, could shape next steps and downstream risks.