McKesson disclosed a cybersecurity incident discovered on August 25 involving unauthorized access to third-party applications and data exfiltration. The healthcare company and pharmaceutical distributor is investigating the scope of the intrusion, including the affected systems and information, and said in an SEC filing that it had not determined the incident to be material.
The ShinyHunters extortion group claimed it used voice-phishing attacks to compromise employees’ Okta single sign-on accounts, then accessed Salesforce and Snowflake environments over four days. The group alleges it stole about 1 TB of data, representing 284 million records, and demanded a $55.24 million ransom; McKesson has not verified the claimed attack path, data volume, record count, patient impact, or data types involved.

See the actors and campaigns active against you right now.
6 events from the most recent confirmed update back to the earliest known activity.
McKesson discovered a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration. The company began an investigation, activated incident-response procedures, and engaged external cybersecurity experts.
ShinyHunters claimed it used voice-phishing to compromise McKesson employees' Okta SSO accounts, access Salesforce and Snowflake environments, and exfiltrate about 1 TB of data between August 21 and August 25. The group alleged the Snowflake data contained roughly 284 million records, but McKesson did not confirm the attack path, data types, volume, or affected applications.
McKesson confirmed that attackers exfiltrated customer data affecting a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. The company said it disrupted the unauthorized access, services remained operational, and impacted individuals would receive complimentary credit-monitoring and identity-protection services.
The domain mckesson[.]claims was identified as allegedly used in the campaign against McKesson. The source noted that its .claims naming pattern has previously been associated with ShinyHunters activity.
ShinyHunters claimed responsibility for the McKesson intrusion and alleged it demanded a $55,236,150 ransom with a 72-hour response deadline. The group claimed McKesson did not respond or negotiate; these claims were not independently verified.
McKesson disclosed the incident in a Form 8-K, stating that its investigation was in early stages and that it had not determined the event to be material or likely to have a material financial or operational impact. It warned customers of possible intermittent service degradation and said it was not proactively disconnecting systems.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
9 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourcetherecord.media
Open sourcehelpnetsecurity.com
Open sourcethecyberthrone.in
Open sourcecysecurity.news
Open sourcemalware.news
Open sourcebleepingcomputer.com
Open sourcemckesson.com
Open sourcesec.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.