Connect with us

NEWS

McKesson Cloud Theft Puts Oncology Patient Files in Play

Hackers claim 284 million McKesson data rows and a $55 million ransom, while the drug wholesaler tells investors the cloud theft is not material.

Published

on

McKesson confirmed on August 28 that hackers broke into third-party cloud apps and stole data tied to oncology and medical-surgical customers. The Irving, Texas, wholesaler said its warehouses are still shipping. It has not said how many people were hit.

The ShinyHunters extortion crew says the path was a phone call, stolen Okta logins, then Salesforce and Snowflake. That is a different problem from a warehouse going dark.

McKesson Says the Warehouses Are Still Shipping

McKesson is the largest of the three public U.S. drug wholesalers, with fiscal 2025 revenue of $359.1 billion. Those three firms together take in more than 90 percent of U.S. drug-distribution revenue. When this company has a bad week, hospitals and clinics feel it in the supply room, not only in a privacy letter.

Chief legal officer Michele Lau signed an August 28 current report that dated the discovery to August 25. The same week, executive vice president, chief information officer and chief technology officer Francisco Fraga told customers the company was not pulling systems offline. He warned of intermittent service degradation that the firm believed might be tied to the incident.

By August 29 the tone had shifted from outage risk to containment. Distribution centers remained open, orders were still being accepted, and product was still moving, Fraga wrote. Customers could connect to McKesson systems as intended, he said, and the company had “reasonable assurance of no ongoing unauthorized activity.”

MCKESSON AT THE POINT OF THE THEFT

  • Headquarters: 6555 State Hwy 161, Irving, Texas, as listed on the August 28 current report.
  • Fiscal 2025 sales: $359.1 billion, with U.S. pharmaceutical distribution the dominant line.
  • Hit units named: a subset of customers in Oncology & Multispecialty and Medical-Surgical, per Fraga’s August 29 letter.
  • Public stance: every line of business still running, per spokesperson Kristina Chang.

Chang said McKesson continues to serve biopharma companies, providers, pharmacies, manufacturers, and governments. The company would not discuss a ransom figure or a headcount of affected people. The second cost sits in the files, not on the dock.

The 284 Million Figure Is a Row Count

ShinyHunters told interviewers it copied about 1 TB of data between August 21 and August 25 and that Snowflake alone yielded about 284 million patient-related records. The group later clarified that the number is a raw count of database rows, or lines, not unique people, and that it had not finished a person-level tally.

That distinction is being flattened in public talk, including posts that set 284 million against the U.S. population as if it were a census of Americans. It is not. McKesson has not confirmed volume, unique patients, or the named cloud platforms. A small sample of files the crew shared was checked against public records and matched, which supports theft of real records without proving the row count.

CONFIRMED VERSUS CLAIMED

Point McKesson has said ShinyHunters has claimed
When access happened Discovered August 25 Data copied August 21 through 25
Where Third-party applications; subset of Oncology & Multispecialty and Medical-Surgical customers Okta logins into Salesforce and Snowflake
How much Not disclosed; investigation still counting About 1 TB; about 284 million Snowflake rows, not unique people
Money No comment on any demand $55,236,150, 72 hours to answer, no reply
Business impact Warehouses shipping; possible brief service degradation Listed the company on a leak site

The group also listed employee records, physician and clinic details, invoices, prescription shipments, internal Salesforce cases, and files on deceased and terminally ill patients. McKesson has not confirmed those fields.

WHAT WE KNOW

  • Company confirmation: unauthorized access to third-party apps and data theft, discovered August 25 and disclosed August 28.
  • Business units: Fraga limited the confirmed theft to a subset of Oncology & Multispecialty and Medical-Surgical customers.
  • Credit help: McKesson said it expects to offer complimentary credit monitoring, identity protection, and a dedicated information line.

WHAT IS UNCONFIRMED

  • Headcount: no unique-person figure from McKesson, and the crew says it has not finished counting individuals.
  • Named platforms: Salesforce, Snowflake, and Okta are actor claims; McKesson has not named the apps.
  • Ransom: the $55,236,150 demand and the claim that McKesson never answered come only from the group.

Until McKesson finishes its count, the 284 million figure is a warehouse-table statistic in someone else’s hands, not a patient registry.

How ShinyHunters Says It Entered McKesson

The crew told interviewers it used voice phishing, or vishing, against multiple McKesson employees, then took over Okta single-sign-on accounts and walked from there into Salesforce and Snowflake. It claims it fully compromised Salesforce, including support cases, and pulled the much larger patient set from Snowflake. Researchers tracking the crew have described lure domains on the.claims top-level domain built to look like a company’s help desk; a separate source told interviewers this incident used mckesson.claims.

That is an identity failure, not a warehouse-software crash, and it sits closer to another identity-layer break-in this year than to a ransomware wiper on a distribution-center floor. Anyone whose Okta ticket can open both a CRM and a patient warehouse should treat help-desk voice resets and MFA-push prompts from August 21 through 25 as the first logs to pull, and should separate a help desk’s right to reset a factor from its right to mint a session into Snowflake.

THE WEEK THE FILES LEFT

  1. August 21, 2026: ShinyHunters says the copy-out window opened.
  2. August 25, 2026: McKesson says it discovered a cybersecurity incident; the group says it finished the theft, made contact, and demanded $55,236,150 with 72 hours to respond.
  3. August 28, 2026: McKesson files the current report, posts its first customer letter, and warns of intermittent service degradation.
  4. August 29, 2026: Fraga’s update names the two business units and says distribution is running.
  5. August 31, 2026: A Dallas class action is filed naming McKesson and CoverMyMeds LLC.

McKesson still directs the public to customer notices signed by Francisco Fraga and says any further account of what was taken will come from its own team. As of Wednesday it had not added a notice after August 29.

The Network Treats 2 Million Patients a Year

Fraga’s letter did not say the US Oncology Network itself was breached. It said stolen data was associated with a subset of customers in Oncology & Multispecialty and Medical-Surgical. That still puts the theft next to McKesson’s cancer-care machine, which the company describes as supporting more than 3,300 providers across 29 states, more than 750 sites of care, and more than 2 million patients a year. About 45 percent of people in the United States live within 20 miles of a practice in that network.

Medical-Surgical is the other named unit, the supplies business McKesson has already said it intends to separate. A theft confined on paper to “a subset of customers” in those two lines still reaches clinic-level identity, drug, and notes data if the actor’s field list is even partly right.

FIELDS THE CREW SAYS IT HOLDS

  • Identity: names, home addresses, dates of birth, phone numbers, emails, and Social Security numbers.
  • Clinical: diagnoses, medications, allergies, illnesses, disabilities, appointment notes, and, in one account the group gave, cancer locations on the body.
  • Care plumbing: patient IDs, medical record numbers, Medicaid numbers, prescriptions, medication shipments, and invoices.
  • The other humans in the file: employee home addresses and job data, plus physician and clinic records.

Diagnoses and notes are worth more on an extortion desk than a shipping delay. A stolen allergy list and a stolen SSN travel together. Employee home addresses turn a company incident into a household one for the people who were tricked on the phone.

McKesson’s 8-K Calls the Incident Not Material

The August 28 filing was a Regulation FD disclosure, not a full Item 1.05 material cybersecurity incident report. Lau’s text is short. The company has not determined that the incident is material or that it has had, or is reasonably likely to have, any material impact on McKesson, including its financial condition or results of operations.

Based on our investigation thus far, including assessments by leading cybersecurity industry experts supporting our response, we’ve confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units.

Francisco Fraga, Executive Vice President, Chief Information Officer and Chief Technology Officer, August 29 customer notice

Those two statements can both be true in securities language and still leave cancer-clinic files with a crew that priced silence at $55,236,150. Materiality here is a company-level money test. It is not a test of whether a diagnosis, a home address, and a Social Security number in the same row are dangerous to the person they describe.

The group says McKesson never answered and never bargained. Chang would not discuss any demand. Paying or not paying does not put the rows back in Snowflake.

A Year of Salesforce Vishing Reached a Drug Wholesaler

Google Threat Intelligence Group has tracked UNC6040 since 2025 as a cluster that uses voice calls, not a Salesforce software flaw, to steal CRM data and then extort the victim. In a June 4, 2025 note on its voice phishing to data extortion campaign, GTIG said the callers impersonate IT support, walk an employee to a connected-app setup page, and get a malicious stand-in for Salesforce Data Loader approved. Google said at the time that roughly 20 organizations had been affected and that, in observed cases, the actors relied on manipulating people rather than exploiting the platform.

GTIG also documented a later move from the CRM into other clouds, including Okta. The McKesson account the crew is now giving interviewers (vishing, Okta, Salesforce, Snowflake, then a nine-figure demand) is that sequence aimed at a wholesaler that stores clinic and patient data beside the trucks. ShinyHunters has already claimed thefts at One Medical, DentaQuest, Medtronic, iRhythm, and AdaptHealth. McKesson is larger, and its files sit closer to drug fulfillment.

The money ask is the same play that has already shown up outside hospitals, including the same extortion script in food plants: copy the data, threaten to publish, wait. A leak-site listing of McKesson appeared as the company was still posting customer letters. Publication is a choice the crew can still make. The copy-out, if the dates it gave are right, already happened.

An Iowa Patient Sues Over Prescription Data Paths

On August 31, William Hall, a Pottawattamie County, Iowa, Medicare patient, filed a class action in the U.S. District Court for the Northern District of Texas, Dallas Division, case 3:26-cv-02958-D, against McKesson and CoverMyMeds LLC. He says a high-cost prescription, a manufacturer assistance program, and later an OptumRx home-delivery quote of about $750 created CoverMyMeds touchpoints, and that a provider in his surgical care used McKesson’s EnterpriseRx pharmacy system. He does not name the drug, the diagnosis, or the provider in the public complaint.

CoverMyMeds, on its own site as cited in that filing, says its network includes more than 50,000 pharmacies. McKesson has not said CoverMyMeds or EnterpriseRx was among the third-party applications in the theft. Hall’s lawyers say those pathways are how his private information could have been in the corpus; they also say McKesson has not identified the apps or the final affected population. The suit is a claim, not a finding.

People whose data may be in the files are in the same spot as patients left to catch a drug-safety risk after a company notice that still lacks names, counts, and a start date for monitoring. McKesson has promised credit monitoring and a phone line once it knows who was in the export. Until that list exists, a clinic patient, a med-surg supply customer, and a phished employee’s household are waiting on the same unfinished count.

Hall’s complaint is on the Dallas docket. McKesson still has not named the applications, the unique people, or whether it was ever asked for $55,236,150. The warehouses, Fraga said, are shipping.

Disclaimer: This article is news reporting on a disclosed cybersecurity incident and related public claims, and it is for information only. It is not medical advice, legal advice, or guidance on identity-theft recovery, credit freezes, or whether any person is in the affected population. Readers who think their information may have been involved should use official McKesson notices and should consult a qualified attorney or an identity-theft specialist before acting on a breach letter, a credit-monitoring offer, or a lawsuit. Figures, unit names, and statuses reflect company filings, customer notices, and actor statements as of September 2, 2026, and may change as McKesson’s investigation and any court case proceed.

Harry is the editor of BUDGY APP, an independent title he owns and runs after ten years in journalism that began on a reporter's desk and ended up at the editor's. Numbers get particular attention here. A percentage in a business story is recomputed from the underlying figures before it goes live, a benchmark in a technology or gaming review is quoted with the conditions it was measured under, and a transfer fee or a lap time in the sports and auto pages is traced back to the club, the league or the timing sheet that published it. The same rule covers news, science, entertainment, lifestyle and travel: if a figure cannot be tied to a filing, a dataset, a transcript or a test Harry ran himself, it does not appear. Readers around the world see prices in the original currency with a conversion alongside. Errors are corrected in the open under a published corrections policy, with the change noted on the article. Questions about any figure reach him at support@budgyapp.com.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending