
Share
A pharmaceutical distributor that touches nearly every U.S. hospital has become the latest healthcare giant hit by extortion hackers, exposing how fragile the systems holding our most sensitive medical information really are.
If you've ever had a prescription filled, chances are your information passed through McKesson's systems at some point without you ever knowing the company's name. That's the uncomfortable reality behind this week's news: the Texas-based pharmaceutical distributor, one of the largest suppliers of medicines and medical technology to hospitals across the country, has confirmed that hackers broke into its cloud-hosted accounts and stole data. The company says it expects "intermittent service degradation" as it works through the fallout.
McKesson disclosed the breach in a statement on its website Friday, acknowledging that intruders accessed several cloud accounts earlier in the week and exfiltrated data. In a separate notice to customers, chief technology officer Francisco Fraga said the stolen information relates to the company's oncology and multispecialty division, along with its medical-surgical unit. Those aren't small corners of the business. McKesson's reach into hospital supply chains means a breach here can ripple outward in ways most people never see until a bill goes wrong or a prescription gets delayed.
The hacking group ShinyHunters, one of the most active data-extortion crews of the past two years, told TechCrunch it gained access by tricking McKesson employees into handing over credentials through phishing and social engineering. Think of it less like breaking a lock and more like convincing someone to hand you the key. That's the pattern with this group: rather than exploiting some exotic software flaw, they exploit trust, patience, and the small human errors that happen inside every large organization.
According to the hackers, the stolen data includes names, addresses, and Social Security numbers, along with protected health information such as diagnoses, medications, allergies, and patient notes. They claim to have pulled millions of rows of data from McKesson's cloud-hosted Snowflake and Salesforce environments, though they say they don't yet know exactly how many individuals are affected. Employee data, including home addresses, was also swept up in the theft. ShinyHunters shared screenshots and samples of the stolen files with TechCrunch, which verified a small subset against public records.
Bleeping Computer, which first reported the connection to ShinyHunters, said the hackers demanded a $55 million ransom in exchange for not publicly releasing the stolen files. That figure alone tells you something about how valuable this kind of data has become on the black market. Medical records don't expire the way a stolen credit card number does. You can cancel a card in five minutes. You cannot cancel your diagnosis history, your allergies, or the fact that you were once treated for a condition you'd rather keep private.
McKesson spokesperson Kristina Chang said in a statement that the company "continues to operate in all lines of business" and reiterated its public statement, adding that McKesson believes there is no ongoing unauthorized activity in its systems. The company declined to answer specific questions from TechCrunch, including what the hackers demanded or how many individuals had their data affected. That silence is common in these situations, but it leaves patients and providers guessing at exactly what's at stake and how quickly it might reach them.

This breach doesn't exist in isolation. It's part of a pattern that's become distressingly familiar over the past year. Last week, medical device maker Boston Scientific was hit by a cyberattack that knocked much of its network offline. Earlier this year, Stryker suffered an incident in which hackers abused internal tools to remotely wipe thousands of employee devices, an attack attributed to pro-Iran hackers. Abbott Laboratories and Medtronic have also faced cyberattacks in recent months. Electronic patient records provider CareCloud and health tech company TriZetto each confirmed breaches affecting more than 3 million patients apiece.
ShinyHunters itself has a growing résumé of healthcare targets. The group has claimed credit for breaches at Amazon-owned One Medical and dental insurance company DentaQuest, both following cyberattacks on their systems. Taken together, these incidents paint a picture of an industry under sustained pressure from groups that have figured out healthcare data is uniquely valuable and uniquely hard to protect.
Why healthcare, specifically? Part of the answer is structural. Hospitals, distributors, and insurers depend on a sprawling web of vendors and cloud platforms to keep patient care moving, which means a single compromised login can open doors across an entire supply chain. Add to that the fact that health records combine financial identifiers like Social Security numbers with deeply personal medical history, and you get a dataset that's worth far more to a criminal than a typical retail breach. It's the difference between stealing someone's wallet and stealing their entire life story.
For the patients whose data may be caught up in this breach, the risks aren't abstract. Stolen Social Security numbers can fuel identity theft for years. Leaked medical histories can be used for targeted scams, insurance fraud, or simply the quiet violation of having your private health struggles exposed without consent. For healthcare providers and hospitals that rely on McKesson to keep medicine and supplies flowing, disruption to services adds a layer of operational risk on top of the privacy concern.
There's also a broader lesson here about accountability. When a distributor most patients have never heard of ends up holding this much sensitive data, the question of who is responsible for protecting it becomes murky fast. McKesson's public statements have been carefully worded, and the company has not detailed how many people are affected or what, if anything, it plans to pay. Until more information comes out, patients and providers alike are left waiting, and in cybersecurity, waiting rarely favors the people whose data is already gone.
Tags
Original Sources
Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson | TechCrunch
↗ https://techcrunch.com/2026/08/31/hackers-claim-millions-of-patient-records-stolen-during-data-breach-at-healthcare-giant-mckesson
About the author
Amara's entry point into AI was an epidemiology role at a London research hospital, where she spent five years studying how digital health tools reached — or conspicuously failed to reach — underserved communities. Watching early algorithmic systems in healthcare quietly entrench existing inequalities, she redirected her career toward the systemic consequences of AI at scale. She covers AI through an unflinching lens: who benefits, who bears the cost, and what evidence actually says versus what the press release claims. Her writing is calm and precise, but she doesn't mistake balance for neutrality.
More from The Steward →This Week's Edition
3 September 2026
22 articles
Related Articles

Fake Citations Generated by AI Are Quietly Shaping Australian Policy Debates
Security & Risk · 6 min

Anthropic Paused AI Training After Claude Took Unauthorized Actions in Cyber Tests
Security & Risk · 5 min

OpenAI Calls for Global "Surge" in Cyber Defense as AI-Powered Attacks Loom
Security & Risk · 5 min
Related Articles

Fake Citations Generated by AI Are Quietly Shaping Australian Policy Debates
Security & Risk · 6 min

Anthropic Paused AI Training After Claude Took Unauthorized Actions in Cyber Tests
Security & Risk · 5 min

OpenAI Calls for Global "Surge" in Cyber Defense as AI-Powered Attacks Loom
Security & Risk · 5 min
More Stories
© 2026 Cedar & Bloom. All rights reserved.