Ransomware Group ShinyHunters Claims Attack on McKesson Corporation

A ransomware group calling itself ShinyHunters claims to have carried out an attack against McKesson Corporation, with the claim dated August 28, 2026. This claim originates from an entry on the group’s own leak-site listing, which is tracked and archived by ransomware.live, a security research platform that monitors ransomware groups’ public extortion sites. As of this writing, McKesson Corporation has not issued any public statement confirming or denying the claim, and no regulator or independent investigator has verified it. BreachLetter is reporting this solely as an unverified claim made by a criminal group, not as an established fact.

What we know — and don’t
  • A group identifying itself as ShinyHunters listed McKesson Corporation on its leak site, with a claimed date of August 28, 2026.
  • McKesson Corporation operates in the healthcare sector, a category that often involves sensitive patient, pharmacy, and clinical partner data — though it is not yet known whether any such data is actually involved in this claim.
  • The specific data types the group claims to have obtained have not been disclosed or confirmed by anyone, including the group itself, at this time.
  • No independent forensic confirmation, company statement, or regulatory filing has verified this claim as of publication.
  • This report is based entirely on a leak-site listing tracked by ransomware.live; it does not reflect confirmed findings from McKesson Corporation or any authority.
What should you do if you have an account with this company?
  • Change your password for any account associated with McKesson Corporation, and avoid reusing that password elsewhere.
  • Enable two-factor authentication (2FA) wherever it’s offered, particularly on email, financial, and healthcare-related accounts.
  • Be cautious of unexpected emails, calls, or texts referencing McKesson Corporation, especially those asking you to click links, verify account details, or provide personal information — these could be phishing attempts riding on this claim.
  • Monitor your financial statements and any healthcare or insurance communications for unfamiliar activity in the coming weeks.
  • Consider signing up for an identity monitoring service like a service like Aura or LifeLock to get alerted if your personal information surfaces somewhere it shouldn’t.
  • Keep records of any suspicious activity in case you need to report it later, even before any official confirmation of this incident.

BreachLetter will update this page if McKesson Corporation confirms this incident, issues a public statement, or if the matter is officially reported to regulators.

Leave a Comment