Full Report
Have I Been Pwned logs leaked records spanning patients, staff, and providers
Analysis Summary
# Incident Report: ShinyHunters Data Breach of McKesson
## Executive Summary
In August 2026, the medical and pharmaceutical supply giant McKesson was targeted in a major cyberattack orchestrated by the threat group ShinyHunters. The incident resulted in the theft of records belonging to approximately 6.4 million individuals, including patients, staff, and healthcare providers, after the company reportedly declined a $55.2 million extortion demand. The breach exposed sensitive medical data, including cancer treatment locations and appointment notes, alongside extensive personally identifiable information (PII).
## Incident Details
- **Discovery Date:** August 2026 (Initial claims by attackers); September 10, 2026 (HIBP scale confirmation)
- **Incident Date:** August 2026
- **Affected Organization:** McKesson
- **Sector:** Healthcare / Pharmaceutical Supply
- **Geography:** United States (supporting 3,300 providers across 29 states)
## Timeline of Events
### Initial Access
- **Date/Time:** August 2026
- **Vector:** Not explicitly disclosed (ShinyHunters typically utilize credential theft or cloud misconfigurations).
- **Details:** Attackers gained unauthorized access to McKesson’s systems, claiming to have accessed 284 million documents.
### Lateral Movement
- **Details:** The breadth of data—spanning marketing, patient care, and employee records—suggests movement across multiple internal databases or cloud storage environments.
### Data Exfiltration/Impact
- **Details:** Large-scale exfiltration of PII and Protected Health Information (PHI). The attackers issued a $55.2 million ransom demand to prevent the leak.
### Detection & Response
- **How it was discovered:** Attacker public claims and internal monitoring.
- **Response actions taken:** McKesson issued a cybersecurity update via their CIO/CTO on August 29, 2026. Data was later analyzed and indexed by "Have I Been Pwned" (HIBP) following the leak.
## Attack Methodology
*Note: Some fields are inferred based on ShinyHunters' historical TTPs and the nature of the data.*
- **Initial Access:** Likely Credential Theft or Exploitation of Third-Party interfaces (based on concurrent industry attacks).
- **Collection:** Gathering of 284 million documents spanning diverse corporate roles.
- **Exfiltration:** Large-scale transfer of sensitive databases.
- **Impact:** Financial extortion attempt ($55.2M) and subsequent public data leak.
## Impact Assessment
- **Financial:** Extortion demand of $55.2 million (unpaid); significant costs expected for victim notification and potential regulatory fines.
- **Data Breach:** 6.4 million records confirmed by HIBP. Data includes names, email/physical addresses, phone numbers, genders, DOBs, employer details, appointment dates/notes, and cancer treatment locations.
- **Operational:** Minimal disruption to shipping (unlike contemporary attacks on Boston Scientific), but significant administrative burden for breach notification.
- **Reputational:** High; exposure of sensitive oncology-related patient data.
## Indicators of Compromise
- **Network indicators:** None disclosed in the report (standard for ShinyHunters attacks which often leverage legitimate but stolen credentials).
- **Behavioral indicators:** Large-scale data egress to external cloud storage; unauthorized access to databases containing PHI.
## Response Actions
- **Containment:** McKesson’s IT leadership initiated response protocols in late August.
- **Eradication:** Investigation into the specific entry point used by ShinyHunters.
- **Recovery:** Notification process initiated for the 6.4 million affected individuals.
## Lessons Learned
- **High Extortion Thresholds:** Threat actors are targeting critical infrastructure with massive eight-figure ransom demands.
- **Data Segregation:** The leak’s scope (marketing vs. clinical data) suggests that lateral movement allowed attackers to bridge different functional silos.
- **Third-Party Risk:** Concurrent attacks in the sector (Veradigm) highlight that API and vendor credential security are critical weak points.
## Recommendations
- **Implement Phishing-Resistant MFA:** To mitigate the risk of credential theft commonly used by groups like ShinyHunters.
- **Enhanced Data Encryption:** Ensure sensitive PHI (like oncology notes) is encrypted at rest and that access is strictly monitored via User and Entity Behavior Analytics (UEBA).
- **API Security:** Review and rotate all third-party API keys and implement strict rate-limiting to prevent bulk data scraping.
- **Defanged URL for reference:** hxxps[://]haveibeenpwned[.]com/Breach/McKesson