Millions of Patient Records Allegedly Stolen in McKesson Data Breach

McKesson, a major U.S. healthcare distributor, is facing a serious new data breach after hackers claimed to have stolen millions of patient records. A notorious hacking group, ShinyHunters, has taken responsibility, saying it accessed several cloud-hosted McKesson accounts following phishing and social engineering tactics.

According to McKesson, the breach involved unauthorized access to multiple cloud systems. The company expects “intermittent service degradation” as it investigates. Key impacted business lines include its oncology & multispecialty and medical-surgical units, where patient and employee data was reportedly compromised.

What Was Taken

The attackers say they obtained sensitive personal and health information from patients: names, addresses, Social Security numbers, diagnoses, medications, allergies, and notes. The breach also included employee data such as home addresses. Data was held in McKesson’s Snowflake and Salesforce environments, but the total number of affected individuals remains uncertain.

ShinyHunters shared samples and screenshots with reporters, portions of which were verified against public records. They also reportedly demanded a $55 million ransom in exchange for not releasing the full set of stolen files.

Broader Context

This isn’t McKesson’s first cybersecurity scare—it joins a growing list of healthcare entities under attack. Recent targets have included medical device companies and health tech firms, many of which handled breaches involving millions of patient records.

The trend highlights vulnerabilities in how medical and health data is stored and protected, especially in cloud environments. Attackers are continuing to exploit weak links in employee training, extreme trust in third-party access, and hybrid infrastructure relying heavily on cloud services.

McKesson has yet to respond publicly to all the allegations, and details remain fluid. What’s clear: this incident could have lasting consequences for patient privacy, regulatory scrutiny, and trust in healthcare data security.

What this means: Large-scale breaches like this not only jeopardize individual privacy but also signal systemic weaknesses in healthcare cybersecurity. As data moves into cloud platforms, organizations will face stricter compliance requirements, growing reputation risk, and the need for stronger employee-awareness and threat detection. Observers will be watching how McKesson handles notification, remediation, and whether regulators step in.