
ShinyHunters Claims 284 Million McKesson Patient Records
ShinyHunters — the hacking group behind the Ticketmaster breach and dozens of others — is claiming they've pulled off one of the largest healthcare data thefts in US history: 284 million patient records from McKesson Corporation, one of the country's largest pharmaceutical distributors.
McKesson has confirmed a cyber incident. The full scope is still being investigated. But the claim alone is alarming enough that anyone who's filled a prescription in America in the last several years should be paying attention.
Who Is McKesson, and Why Does This Matter?
McKesson isn't a name most people recognize, but the company touches virtually every American's healthcare experience. It's one of the largest distributors of pharmaceuticals in the United States — supplying drugs to hospitals, pharmacies, and healthcare providers nationwide. The company ranked 9th on the Fortune 500 in 2025.
That means its data isn't just McKesson's data. It's a centralized repository of patient information from across the healthcare ecosystem — names, dates of birth, prescription histories, insurance details, and potentially Social Security numbers and financial information.
284 million records would represent nearly every person in the United States.
Who Is ShinyHunters?
ShinyHunters is a financially motivated hacking group that has been operating since at least 2020. They've claimed responsibility for breaches at Ticketmaster (560 million records), Santander Bank, AT&T, and dozens of others. They typically sell stolen data on criminal forums — sometimes for millions of dollars.
They are not amateurs. They are persistent, skilled, and they've been right before.
How Did They Get In?
According to reporting from TechJack Solutions and other sources, ShinyHunters gained initial access through a combination of vishing (voice phishing — calling employees and impersonating IT support) and an Okta compromise. The attack vector is similar to the method used against MGM Resorts in 2023, which caused over $100 million in damages.
The playbook: call an employee, convince them to hand over credentials or approve an authentication request, use those credentials to access Okta (an identity management platform many large companies use), then move laterally through the network from there.
It's a method that bypasses most technical defenses. It targets people, not software.
What McKesson Has Confirmed
As of this writing, McKesson has acknowledged a cyber incident and stated they are investigating. The company has not confirmed the 284 million figure or the specific data types involved.
That's not unusual. Companies rarely confirm the worst-case version of a breach while an investigation is active. It's also worth noting that ShinyHunters has a documented history of exaggerating breach scope — but they've also been largely accurate in past claims.
SC World and BleepingComputer are both tracking the story; BleepingComputer notes McKesson has engaged third-party forensic investigators.
What Data May Be Involved
ShinyHunters claims the stolen records include:
- Full names and dates of birth
- Addresses and contact information
- Prescription and medical history
- Health insurance details
- In some cases, Social Security numbers
The HIPAA Journal notes that if even a fraction of this data is confirmed, it would rank among the worst healthcare breaches ever recorded — surpassing the 2024 Change Healthcare breach, which affected an estimated 190 million Americans.
What Should You Do Right Now?
You can't know for certain if your data was taken until McKesson or regulators release more information. But you can move now on things that will protect you regardless:
Monitor your credit. File a free credit freeze with all three bureaus — Equifax, Experian, TransUnion. A freeze prevents anyone from opening new credit in your name, even if they have your Social Security number. It's free and reversible.
Watch for suspicious prescriptions. Medical identity theft — where someone uses your insurance to get drugs or treatments — is a real and underreported crime. Check your insurance Explanation of Benefits (EOB) statements for anything you don't recognize.
Be suspicious of incoming calls. After a breach this size, phishing campaigns targeting victims will follow. If someone calls claiming to be from McKesson, your pharmacy, or your insurer — hang up and call back on the official number.
Check HaveIBeenPwned. Troy Hunt's site aggregates known breach data. It may take weeks or months for this data to surface there, but it's worth bookmarking.
The Bigger Picture
This breach — if the scale holds — isn't just a McKesson problem. It's a systemic one.
Healthcare data is uniquely valuable to criminals. It can't be changed the way a password can. A stolen Social Security number paired with a medical history is worth far more on the dark web than just a credit card number. And healthcare companies have historically been slower to modernize their security than financial institutions.
The attack method here — vishing plus identity platform compromise — is now a proven formula that well-resourced groups keep returning to. Until companies treat their help desks and IT support workflows as security perimeters, not just customer service functions, this won't be the last breach of this kind.
🔑 Key Terms
ShinyHunters — a financially motivated cybercriminal group known for large-scale data theft and selling stolen data on criminal forums. Active since at least 2020.
Vishing (Voice Phishing) — a social engineering attack carried out over the phone. Attackers impersonate IT staff, executives, or support teams to trick employees into handing over credentials.
Okta — a cloud-based identity and access management platform used by thousands of companies. If an attacker compromises Okta credentials, they may gain access to many internal systems at once.
HIPAA — the Health Insurance Portability and Accountability Act. US law that sets standards for protecting patient health information. Breaches of protected health information (PHI) carry significant regulatory penalties.
PHI (Protected Health Information) — any health data that can be linked to a specific individual. The most sensitive category under HIPAA.
Medical Identity Theft — using someone else's identity to fraudulently obtain healthcare services, prescriptions, or insurance benefits.
Dark Web — a part of the internet not indexed by search engines and accessible only through special software. Often used to buy and sell stolen data, credentials, and access.
📚 Sources
BleepingComputer — McKesson discloses breach after ShinyHunters claims patient data theft SC World — McKesson discloses data breach after ShinyHunters claims theft of 284 million records HIPAA Journal — ShinyHunters Claims Theft of 284M Records from Healthcare Giant McKesson Cybernews — McKesson Breach: ShinyHunters Claims 284m Patient Records Help Net Security — ShinyHunters claims it stole 284 million patient records from McKesson Malwarebytes — McKesson confirms cyber incident after ShinyHunters claims patient data theft TechJack Solutions — ShinyHunters Breaches McKesson via Vishing and Okta Compromise Cyber Insider — ShinyHunters claims McKesson data breach exposing 284 million patients