McKesson told customers on August 28, 2026 that attackers accessed and exfiltrated data from third-party applications, and filed an 8-K the same day. ShinyHunters claims about 284 million data rows, roughly a terabyte, taken from the company's Salesforce and Snowflake environments between August 21 and August 25. The group set a ransom of $55,236,150 with a 72-hour deadline. McKesson let it pass without negotiating.
The way in was a phone call. Attackers vished multiple employees while posing as help desk and IT staff, backed by the lookalike domain mckesson[.]claims, and took over the victims' Okta single sign-on accounts. Those sessions reached the Salesforce environment, support cases included, and the Snowflake data warehouse.
The claimed haul spans the Oncology & Multispecialty and Medical-Surgical units. It includes names, addresses, dates of birth, Social Security numbers, patient and medical record numbers, Medicaid numbers, medication and allergy details, diagnoses, and appointment records. Employee data and internal communications are in the set too. Rows are not unique patients, and this group has a record of claiming more than later verification supports, so treat 284 million as an upper bound until notification filings land.
McKesson says its initial containment actions appear to have been successful, that distribution centers are operating normally, and that customers do not need to take any action. The affected oncology unit serves about 3,300 providers across 29 states. The investigation into full scope is still open.
The playbook matches the run that put Baxter on the ShinyHunters leak site two weeks earlier: vish an employee, ride the single sign-on session into Salesforce, then pull CRM and warehouse data at leisure. A password policy does not survive a convincing help desk call; phishing-resistant MFA on the SSO tier and callback verification for credential resets are the controls that mattered here.