The numbers
Timeline
💉Why healthcare data is worth more than a password
The claimed dataset does not read like a typical customer list. It includes prescriptions, diagnoses, allergy information, and — specifically named in the claim — records of deceased and terminally ill patients. That level of detail cannot be reset like a password, and it is precisely the kind of information that makes a fraudulent call about a prescription, an insurance claim or a medical bill sound credible.
Source: Help Net Security, TechCrunch, 31/08/2026.👥ShinyHunters: one group, several claims, one at a time
ShinyHunters is a financially motivated group with a long track record of large-scale data theft claims. In the same season it also claimed Baxter and RingCentral, and has been linked to the ReliaQuest incident. A busy attacker is not evidence that every figure it publishes is accurate: each claim is verified on its own terms, against what the named company actually confirms.
Source: TechCrunch, Privacy Guides, 31/08–03/09/2026.🏥Not the only healthcare breach this season
CareCloud, a cloud-based records and billing platform used by more than 45,000 US healthcare providers, confirmed a breach of its AWS environment in March 2026. Initial disclosure covered around 345,000 people; by August, the confirmed figure had grown to 3,756,469 patients, with Social Security numbers, government IDs, medical records, and for some victims, full card numbers including CVVs exposed. It is a separate incident from McKesson, disclosed in the same period.
Source: Privacy Guides, data breach roundup, 28/08–03/09/2026.What this changes for you
If you have used a pharmacy, clinic or hospital system connected to McKesson, there is no way to know whether your specific record was included, and no action that undoes an exposed medical history. What is reasonable to expect is the follow-on contact: a call or message that cites a real prescription, a real appointment, or a real diagnosis to sound legitimate.
Frequently asked questions
Has McKesson confirmed the breach?
Yes, McKesson has confirmed a data breach, detected on 25 August 2026. That confirmation covers the fact of an intrusion. The figure of 284 million patient records comes from the ShinyHunters group itself and has not been confirmed by McKesson at that scale.
What kind of data is claimed to be exposed?
According to the claim, an unusually complete range: names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, emails, Medicaid numbers, medical record numbers, medication and allergy information, diagnoses, appointment details, and physician information. The claim also lists information on deceased and terminally ill patients, prescription and shipment data, invoices, employee records, and Salesforce data, plus details on the healthcare providers and clinics that use McKesson's services.
Who is ShinyHunters?
ShinyHunters is a financially motivated hacking group with a long history of large-scale data theft claims, active well before this incident. In the same window they also claimed breaches at Baxter (7.1 million Salesforce records) and RingCentral (1.6 million accounts) and were linked to the ReliaQuest incident. A pattern of claims from the same group is not proof that every number is accurate — each case is verified separately.
Is this the only healthcare breach of this scale in 2026?
No. CareCloud, a cloud-based records and billing platform used by more than 45,000 US healthcare providers, confirmed in March 2026 a breach of its AWS environment. Initial disclosure covered around 345,000 people; by August the confirmed figure had grown to 3,756,469 patients, with Social Security numbers, government IDs, medical records and, for some victims, full card numbers exposed.
Can Egidio detect scams that use this kind of data?
Egidio cannot know whether your own records were part of this breach, and it cannot verify who is calling or texting you. What it recognises are the known patterns of a scam approach: manufactured urgency, a request for money, codes or personal details, an unusual channel. A caller who already knows your prescription history is not proving they are your pharmacy — they are proving they have your data.
Further reading
Egidio — Threat Laboratory, « McKesson breach: 284M patient records claimed », egidio.app/en/laboratoire/mckesson-shinyhunters-patient-data-breach/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.