McKesson Hit by Data Theft and Extortion Attack by ShinyHunters
Healthcare giant McKesson disclosed a cyberattack resulting in data theft and temporary service interruptions, with the threat group ShinyHunters claiming responsibility and demanding over $55 million.

McKesson, a critical player in the North American pharmaceutical distribution chain, has disclosed a significant cyberattack that led to data theft and temporary disruptions to its services. The company confirmed that attackers gained unauthorized access to some of its third-party applications, resulting in the compromise of data belonging to a subset of its customers across its oncology, multispecialty, and medical-surgical business units.
The healthcare vendor, which distributes approximately one-third of all pharmaceuticals used in North America and reported over $403 billion in revenue for the past fiscal year, was targeted by threat actors who initiated a four-day intrusion beginning August 21. McKesson discovered the breach on August 25 and immediately activated its incident response protocols, enlisting the support of leading cybersecurity experts. The company stated that it has a reasonable assurance of no ongoing unauthorized activity within its systems and that customers can continue to use its services as intended.
While McKesson has not officially identified the cybercriminal group behind the attack, the notorious threat group ShinyHunters has claimed responsibility and added the company to its data-leak site. ShinyHunters is known for targeting large organizations, exfiltrating substantial amounts of sensitive data, and then demanding significant ransoms to prevent its public release. McKesson declined to comment on ShinyHunters' claims or any potential ransom demands.
Adding to the urgency, ShinyHunters is reportedly demanding over $55 million from McKesson, with a deadline of September 1. The circumstances of the attack align with ShinyHunters' typical modus operandi, which often involves exploiting weaknesses in identity and access management or using social engineering to gain access to cloud-hosted environments rich with sensitive data. These attacks are particularly insidious as they can be difficult to detect early, often mimicking legitimate user activity and bypassing traditional security alerts.
This incident echoes a pattern of attacks by ShinyHunters against major cloud platforms and service providers. The group has previously been linked to breaches affecting Oracle, Salesforce, and Snowflake, and was responsible for a widespread compromise impacting hundreds of Salesloft Drift customers last summer. More recently, ShinyHunters targeted Canvas, a popular educational platform, causing outages and data theft, and ultimately leading to a payment by the platform's operator, Instructure.
The FBI has previously issued public service announcements warning about ShinyHunters' tactics, highlighting their pressure techniques and data extortion demands. In late July, just weeks before the McKesson breach, the Health-ISAC also alerted organizations in the healthcare sector to an increase in successful attacks by ShinyHunters, underscoring the growing threat to critical infrastructure and sensitive patient data.
The attack on McKesson underscores the persistent and evolving threat posed by data extortion groups to the healthcare sector. The compromise of a major distributor highlights the interconnectedness of the supply chain and the potential for widespread disruption when such critical entities are targeted. The ongoing investigation and potential ransom negotiations will be closely watched as the industry grapples with the fallout.