McKesson discloses breach after ShinyHunters claims patient data theft

McKesson discloses breach after ShinyHunters claims patient data theft
McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data exfiltration, while ShinyHunters claimed it stole 284 million patient data records. The attackers reportedly used vishing to compromise Okta accounts and access McKesson’s Salesforce and Snowflake environments. #McKesson #ShinyHunters #Okta #Salesforce #Snowflake

Keypoints

  • McKesson confirmed unauthorized access to third-party applications and data theft.
  • The company said it discovered the incident on August 25, 2026.
  • ShinyHunters claimed it used vishing to compromise employee Okta accounts.
  • The threat actor allegedly accessed McKesson’s Salesforce and Snowflake environments.
  • McKesson has not yet disclosed the full scope of the stolen information.

Read More: https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/