McKesson Confirms Break-In After Hackers Claim 284 Million Patient Records Stolen
The US pharmaceutical distribution giant says intruders reached third-party apps holding limited data. The ShinyHunters gang claims a haul far larger than McKesson admits.

Key points
- McKesson, the largest US pharmaceutical distributor, disclosed on 14 November 2025 that intruders reached data held in third-party business applications.
- The extortion group ShinyHunters claims it stole 284 million patient records, a figure McKesson has not confirmed.
- McKesson says the affected systems held limited business information and no core patient medical records or prescription data.
- The company says it cut off the access, brought in outside investigators, and notified law enforcement.
- Patients are urged to watch for unusual medical bills, insurance letters, or phishing emails referencing pharmacies.
McKesson, one of the biggest drug distributors on the planet, has confirmed a cybersecurity incident. The company moves medicines from manufacturers to pharmacies, hospitals and clinics across the United States. On 14 November it told regulators that outsiders got into some of its third-party business applications, meaning software McKesson rents from other vendors rather than runs itself.
The disclosure came the same week that ShinyHunters, a well-known extortion crew, started boasting on a leak site. The group claims it walked off with 284 million patient records. That is a staggering number. It would cover close to every adult in the country.
McKesson tells a smaller story. In its statement, the company says the touched systems held "limited" information tied to its business operations. It says core patient medical records, prescription histories and payment card data were not in those systems. The company has not published a victim count.
What actually got taken?
McKesson has not said, in detail. The company describes the exposed material as limited business data sitting inside third-party apps, and says its main pharmacy and distribution systems were untouched. ShinyHunters, meanwhile, is advertising a 284 million-record trove. Neither figure has been independently verified.
This gap between what a victim admits and what an extortion crew claims is normal. Criminal groups inflate numbers to push a ransom. Victims lean cautious while lawyers and forensics teams count rows. The truth usually lands somewhere in the middle, and it can take months to surface, as reporting by BleepingComputer on similar ShinyHunters cases has shown.
How did the hackers get in?
McKesson has not named the vector. Based on the wording of the notice, the entry point was a third-party application rather than McKesson's own network. That pattern has become the defining breach story of 2025.
ShinyHunters spent much of this year raiding customer instances of Salesforce, the sales and customer-service cloud platform. In many of those cases, attackers tricked staff into approving a malicious connected app through OAuth, the standard (RFC 6749) that lets one application ask another for access on a user's behalf. Once the app was approved, the criminals could pull data out through the API without ever touching a password.
Whether McKesson's incident followed that exact script is not yet public. It fits the shape.
Would MFA have helped?
Honestly, only partly. Multi-factor authentication, the second step after a password (usually a code or a tap on your phone), stops password theft cold. It does not stop a user from clicking "Allow" on a rogue OAuth consent screen. That is an authorisation problem, not an authentication one. The fix there is tighter control over which third-party apps staff can connect, and review of the scopes those apps request.
What should patients do?
Nothing urgent, but pay attention. Watch for medical bills for care you did not receive, insurance letters mentioning unfamiliar providers, and emails or texts claiming to be from your pharmacy that ask you to click a link or confirm details. If McKesson eventually determines your data was involved, it is legally required to notify you and, in most cases, offer credit monitoring.
Do not act on unsolicited messages that claim to come from McKesson itself. Any real notice will arrive by post.
What happens next?
McKesson says it has ended the unauthorised access, hired outside forensics specialists, and told law enforcement. Expect state attorneys general and the US Department of Health and Human Services to open their own reviews if protected health information turns out to be in the mix. A clearer victim count, and a clearer picture of what ShinyHunters actually holds, will follow in the weeks ahead.



