McKesson Was Breached by a Phone Call, Not a Zero-Day
shinyhunters is claiming to have stolen 284 million patient records from mckesson and demanded US$55.2 million to keep the data from being released. this is on-brand for shinyhunters, which means the claim is worth taking seriously, but not taking at face value. the gap is worth examining.
mckesson is a name you likely have never heard of before. i sure as hell never heard of them until today. but chances are once you read this story you will not forget the name. mckesson distributes roughly a third of all prescription medicines in north america.
as such, a huge amount of patient data flows through their infrastructure from thousands of hospitals, pharmacies, and clinics that are not mckesson, but whose records touch its systems. this is what makes a breach here so heavy. the blast radius is not mckesson's customers. it is a huge slice of the country's healthcare data.
here is what has actually been confirmed. mckesson filed with the sec that it detected a cyber security incident on august 25 involving unauthorized access to third-party applications and data exfiltration. it says the investigation is early and points to a subset of two business units. that is the verified floor. everything beyond that is a mere claim.
shinyhunters is making said claim. specifically, they say they took 284 million records. read that carefully. records, not patients. 284 million is the claimed number of database rows, and the group itself admits it maps to tens of millions of people, not 284 million individual patients. this distinction is incredibly important. the scary headline number and the actual human number are not the same, and the group has an incentive to make the stash sound enormous. gotta pound your hands on your big scary chest, right?
so how much do you trust them. this is where it gets uncomfortable. shinyhunters has been a highly effective extortion crew in 2026, tearing through healthcare, telecom, and insurance with one boring, repeatable playbook. call an employee. pretend to be it support. talk them into handing over their single sign-on login. then walk into the company's cloud data platforms, salesforce, snowflake, and drain them.
they claim they pulled roughly a terabyte out of mckesson this way over four days. this is shinyhunters tradecraft. it is what they do.
mckesson has confirmed data exfiltration, but not this exact attack path or volume. mckesson has also not confirmed the demand or any negotiation.
so many successful adversaries do not need to use sophisticated attacks to conduct a successful breach. all they need is low hanging fruit.
in this case, the entry point was not some elite zero-day. it was a phone call. an employee, a convincing voice, a stolen login. some of the most valuable healthcare data in the country now sits behind cloud identity systems that a well-delivered lie can sometimes open. we spent years hardening the perimeter, and the door that keeps getting used is a human being who wanted to be helpful.
"humans are the weakest link in the chain" is a refrain we likely will never stop hearing.
you cannot patch that with software. human behavior does not change that easily. and until that changes, the size of the next number is just a matter of which company picks up the phone.