Feed›Data Breach›McKesson discloses breach after ShinyHunters claims patient ...
Data BreachBleeping Computer
8.5 — CRITICAL

McKesson discloses breach after ShinyHunters claims patient data theft

📅 28 August 2026 at 22:40 UTC📰 Bleeping ComputerView original source ↗
McKesson discloses breach after ShinyHunters claims patient data theft

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records. [...]

🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview

ShinyHunters claimed to have stolen approximately 284 million patient data records from McKesson, a major U.S. healthcare company and pharmaceutical distributor, through voice phishing and social engineering attacks on multiple employees' Okta single sign-on accounts.

⚙️Technical Details
Affected Systems
OktaSalesforceSnowflake
Attack Vectors
voice phishingsocial engineering
💥Impact Assessment
Severity: high
Who Is at Risk
patients and healthcare providers using McKesson's services
🛡️Recommended Actions
1Implement multi-factor authentication for all employees' Okta accounts.
2Conduct regular security awareness training to prevent social engineering attacks.
3Monitor Salesforce and Snowflake environments for suspicious activity.
📦Affected Products
OktaSalesforceSnowflake

Read the full article

This is a curated summary. The complete article is available at Bleeping Computer.

Read on Bleeping Computer ↗
← Back to feed