Egidio
Dossier · 6 September 2026

McKesson breach: 284 million patient records claimed

McKesson, one of the largest pharmaceutical distributors in the United States, has confirmed a data breach detected on 25 August 2026. The group ShinyHunters claims to have stolen 284 million patient records — a figure McKesson has not confirmed at that scale. What is established, what is only claimed, and why healthcare data is worth more to a scammer than almost anything else.

Protect my phone with Egidio Free for calls · 100% on your phone · no account needed
⚠️ What "confirmed" means here. McKesson has confirmed a breach — the fact of unauthorised access. It has not confirmed the headline figure of 284 million records, which comes from the attackers themselves. This page keeps the two apart throughout.

The numbers

25 Aug
2026 — the date McKesson has confirmed detecting the intrusion.
Help Net Security, 31/08/2026.
284M
Patient records claimed stolen by ShinyHunters — not confirmed by McKesson at this scale.
TechCrunch, Help Net Security, 31/08/2026.
3.76M
Patients confirmed affected in a DIFFERENT healthcare breach disclosed the same season — CareCloud, revised up from an initial 345,000.
Privacy Guides, roundup 28/08–03/09/2026.
0
Confirmations by McKesson of the specific 284M figure, at the time of writing.
Checked 06/09/2026.

Timeline

CONFIRMED
25 August 2026
McKesson detects unauthorised access to its systems and confirms a data breach. The company has not disclosed a scope figure of its own.
CLAIMED
31 August 2026
The group ShinyHunters claims responsibility and states it holds 284 million patient records, describing an unusually wide range of data: names, addresses, dates of birth, Social Security numbers, patient IDs, Medicaid numbers, medical record numbers, medications, allergies, diagnoses, appointment details, and physician information — plus employee and Salesforce records, and information on the clinics and providers that use McKesson's services.
CLAIMED, SAME PERIOD
Late August – early September 2026
The same group claims two further breaches in the same window: Baxter (7.1 million Salesforce records) and RingCentral (1.6 million accounts). ShinyHunters is also linked to the ReliaQuest incident. None of these figures independently confirm the McKesson claim — a pattern of activity from one group is not proof of any single number.

💉Why healthcare data is worth more than a password

The claimed dataset does not read like a typical customer list. It includes prescriptions, diagnoses, allergy information, and — specifically named in the claim — records of deceased and terminally ill patients. That level of detail cannot be reset like a password, and it is precisely the kind of information that makes a fraudulent call about a prescription, an insurance claim or a medical bill sound credible.

Source: Help Net Security, TechCrunch, 31/08/2026.

👥ShinyHunters: one group, several claims, one at a time

ShinyHunters is a financially motivated group with a long track record of large-scale data theft claims. In the same season it also claimed Baxter and RingCentral, and has been linked to the ReliaQuest incident. A busy attacker is not evidence that every figure it publishes is accurate: each claim is verified on its own terms, against what the named company actually confirms.

Source: TechCrunch, Privacy Guides, 31/08–03/09/2026.

🏥Not the only healthcare breach this season

CareCloud, a cloud-based records and billing platform used by more than 45,000 US healthcare providers, confirmed a breach of its AWS environment in March 2026. Initial disclosure covered around 345,000 people; by August, the confirmed figure had grown to 3,756,469 patients, with Social Security numbers, government IDs, medical records, and for some victims, full card numbers including CVVs exposed. It is a separate incident from McKesson, disclosed in the same period.

Source: Privacy Guides, data breach roundup, 28/08–03/09/2026.

What this changes for you

If you have used a pharmacy, clinic or hospital system connected to McKesson, there is no way to know whether your specific record was included, and no action that undoes an exposed medical history. What is reasonable to expect is the follow-on contact: a call or message that cites a real prescription, a real appointment, or a real diagnosis to sound legitimate.

🔒 The habit that survives any leak: hang up and call back on a number you already have — from your insurance card, a past bill, or the pharmacy's official number you looked up yourself. Never the number given by the person contacting you. See from leak to scam for how stolen data becomes a script.

Frequently asked questions

Has McKesson confirmed the breach?

Yes, McKesson has confirmed a data breach, detected on 25 August 2026. That confirmation covers the fact of an intrusion. The figure of 284 million patient records comes from the ShinyHunters group itself and has not been confirmed by McKesson at that scale.

What kind of data is claimed to be exposed?

According to the claim, an unusually complete range: names, addresses, dates of birth, Social Security numbers, patient IDs, phone numbers, emails, Medicaid numbers, medical record numbers, medication and allergy information, diagnoses, appointment details, and physician information. The claim also lists information on deceased and terminally ill patients, prescription and shipment data, invoices, employee records, and Salesforce data, plus details on the healthcare providers and clinics that use McKesson's services.

Who is ShinyHunters?

ShinyHunters is a financially motivated hacking group with a long history of large-scale data theft claims, active well before this incident. In the same window they also claimed breaches at Baxter (7.1 million Salesforce records) and RingCentral (1.6 million accounts) and were linked to the ReliaQuest incident. A pattern of claims from the same group is not proof that every number is accurate — each case is verified separately.

Is this the only healthcare breach of this scale in 2026?

No. CareCloud, a cloud-based records and billing platform used by more than 45,000 US healthcare providers, confirmed in March 2026 a breach of its AWS environment. Initial disclosure covered around 345,000 people; by August the confirmed figure had grown to 3,756,469 patients, with Social Security numbers, government IDs, medical records and, for some victims, full card numbers exposed.

Can Egidio detect scams that use this kind of data?

Egidio cannot know whether your own records were part of this breach, and it cannot verify who is calling or texting you. What it recognises are the known patterns of a scam approach: manufactured urgency, a request for money, codes or personal details, an unusual channel. A caller who already knows your prescription history is not proving they are your pharmacy — they are proving they have your data.

Install Egidio — free →

Further reading

Cite this page Egidio — Threat Laboratory, « McKesson breach: 284M patient records claimed », egidio.app/en/laboratoire/mckesson-shinyhunters-patient-data-breach/. Licensed CC BY 4.0.

Free to reuse, including commercially, with attribution. Reuse terms.