ShinyHunters Extortion Group Claims 284M-Record McKesson Corporation Data Breach via Vishing and Salesforce/Snowflake Compromise

ShinyHunters Extortion Group Claims 284M-Record McKesson (TL-2026-2208) is a critical-severity data breach, first published 2026-08-29. It is attributed to ShinyHunters with high confidence, affects McKesson Corporation Salesforce environment (CRM / support cases), maps to 10 MITRE ATT&CK techniques (T1078.004, T1213, T1530), and is covered by 9 detection rules and 12 indicators of compromise.

Key facts for TL-2026-2208

Threat ID
TL-2026-2208
Severity
CRITICAL
Status
ACTIVE
Category
DATA_BREACH
First published
2026-08-29
Last reviewed
2026-08-29
Attribution
ShinyHunters
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
health, pharmaceutical distribution
Target regions
North America
Detection rules
9
Indicators of compromise
12

Malware and tooling in ShinyHunters Extortion Group Claims 284M-Record McKesson

Malware and tooling: scattered lapsus$ hunters

ShinyHunters claims to have stolen roughly 284 million data records (~1TB, exfiltrated Aug 21-25, 2026) from healthcare distributor McKesson Corporation by vishing employees, registering the lookalike domain mckesson[.]claims, compromising employee Okta SSO accounts, and pivoting into McKesson's Salesforce and Snowflake environments. The group is demanding $55,236,150 with a 72-hour deadline that has since lapsed without payment; McKesson disclosed the incident on August 28, 2026 and says its investigation is in early stages with no material impact yet determined.

How ShinyHunters Extortion Group Claims 284M-Record McKesson works

On August 28, 2026, healthcare and pharmaceutical distribution giant McKesson Corporation disclosed a cybersecurity incident describing 'unauthorized access to third-party applications and exfiltration of data,' after the ShinyHunters extortion group told BleepingComputer it had stolen approximately 284 million data records (~1TB) from the company. ShinyHunters says the intrusion began with voice-phishing (vishing) calls against McKesson employees, in which callers impersonated internal IT/help-desk or security staff and directed targets to a fraudulent single sign-on (SSO) page. The group registered the lookalike domain mckesson[.]claims to support this impersonation, following a broader ShinyHunters domain-generation pattern -- registering 'company[.]claims' lookalike domains keyed to each target's name or abbreviation -- that ReliaQuest's Threat Research team publicly warned about on August 17, 2026, days before ReliaQuest itself was targeted via reliaquest[.]claims (one employee entered credentials and approved a fraudulent MFA push, granting brief view-only access to ReliaQuest's identity dashboard before device-trust controls blocked further movement; no ReliaQuest customer data was confirmed stolen).

Against McKesson, ShinyHunters claims the vishing calls led to compromise of multiple employees' Okta SSO accounts, which were then used to access McKesson's Salesforce environment (described by the actor as 'fully compromised,' including support cases) and a larger volume of patient-related data held in Snowflake. The actor states exfiltration ran over four days, August 21-25, 2026, totaling roughly 1TB / 284 million records -- a figure ShinyHunters itself later clarified is a raw row/line count rather than a count of unique individuals, consistent with the group's history of overstated headline numbers. Claimed stolen data spans patient PII/PHI (names, addresses, dates of birth, SSNs, patient IDs, phone numbers, email addresses, Medicaid numbers, medical record numbers, medication/allergy information, illnesses, disabilities, appointment information), physician/provider data, employee records, and internal Salesforce support-case communications.

McKesson discovered the incident on August 25, 2026 and activated its incident response protocols; the same day, ShinyHunters issued a $55,236,150 ransom demand with a 72-hour deadline. As of McKesson's August 28 public disclosure, the company had not responded to or negotiated with the group, and the deadline had lapsed without payment. McKesson's statement describes the investigation as being in 'early stages' with no determination yet of material impact.

ShinyHunters is tracked as a loose, multinational criminal ecosystem (aliases/personas include ShinyCorp and members using handles such as Hollow, Noct, and Depressed) operating alongside and overlapping with the Scattered Spider and Lapsus$ collectives under the broader 'Scattered LAPSUS$ Hunters' (SLSH) umbrella; industry tracking designations for related activity clusters include UNC6040 (the Salesforce-vishing cluster), among others. The group has run a sustained campaign of Okta/SSO vishing against SaaS environments (Salesforce, Snowflake) through 2025-2026, with prior high-profile incidents including the Salesloft/Drift OAuth-token campaign (~1.5 billion records across roughly 760 Salesforce orgs, Aug-Sep 2025), the Gainsight-linked Salesforce campaign (200+ instances, Nov 2025), a wave of Okta-vishing intrusions against Wynn Resorts, Panera Bread, Harvard, Princeton, and the University of Pennsylvania (Jan 2026), and the Instructure/Canvas breach (275M records / 3.65TB, Apr-May 2026). Several affiliates have been arrested since 2022-2025 (including Sebastien Raoult and Matthew D. Lane), but the group's decentralized structure has allowed operations to continue.

MITRE ATT&CK techniques used in TL-2026-2208

Initial Access

T1078.004 Valid Accounts: Cloud Accounts; T1566.004 Phishing: Spearphishing Voice

Privilege Escalation

T1078.004 Valid Accounts: Cloud Accounts

Persistence

T1078.004 Valid Accounts: Cloud Accounts

Collection

T1213 Data from Information Repositories; T1530 Data from Cloud Storage

Exfiltration

T1567 Exfiltration Over Web Service

Resource Development

T1583.001 Acquire Infrastructure: Domains

Reconnaissance

T1589.002 Gather Victim Identity Information: Email Addresses

Credential Access

T1621 Multi-Factor Authentication Request Generation

Impact

T1657 Financial Theft

Defense Evasion

T1684.001 Impersonation

Affected products and versions in ShinyHunters Extortion Group Claims 284M-Record McKesson

  • McKesson Corporation — Salesforce environment (CRM / support cases)
    Vulnerable versions: SaaS tenant compromised via stolen employee credentials, not a software version
  • McKesson Corporation — Snowflake environment (patient/employee data warehouse)
    Vulnerable versions: SaaS tenant compromised via stolen employee credentials, not a software version
  • McKesson Corporation — Okta SSO (employee identity accounts)
    Vulnerable versions: Multiple employee accounts compromised via vishing, not a software version

Remediation for ShinyHunters Extortion Group Claims 284M-Record McKesson

Immediate actions

  • Force re-authentication and rotate credentials for all Okta SSO accounts, prioritizing employees who may have received vishing calls around Aug 21-25, 2026
  • Revoke and re-issue all active Salesforce and Snowflake sessions, API keys, and OAuth tokens tied to potentially compromised accounts
  • Block and monitor for mckesson[.]claims and newly registered company[.]claims lookalike domains at email and web gateways
  • Audit Salesforce support-case access logs and Snowflake query history for the Aug 21-25, 2026 window for anomalous bulk read/export activity

Workarounds

  • Require call-back verification to a pre-registered employee number before actioning any phone-requested SSO or MFA reset
  • Require secondary approval for MFA device enrollment/changes on privileged or newly-registered devices

Longer-term hardening

  • Deploy phishing-resistant MFA (FIDO2/WebAuthn passkeys) for all SSO-federated accounts, especially helpdesk-privileged and SaaS-admin roles
  • Enforce conditional access and device-trust policies on Okta and downstream SaaS applications (device-trust controls stopped further access in the related ReliaQuest incident)
  • Audit and least-privilege-scope OAuth/connected-app integrations into Salesforce and Snowflake
  • Run recurring vishing-resistance training and enforce out-of-band identity verification for any SSO/MFA reset request received by phone

Timeline of ShinyHunters Extortion Group Claims 284M-Record McKesson

  • ReliaQuest's Threat Research team publicly warns of a widespread ShinyHunters campaign registering 'company[.]claims' lookalike domains to impersonate targeted organizations' help desk/IT/security teams.
  • ShinyHunters begins exfiltrating data from McKesson's Salesforce and Snowflake environments, per the group's own account given to BleepingComputer.
  • The same 'company.claims' campaign infrastructure is used against ReliaQuest via reliaquest[.]claims; one employee approves a fraudulent MFA push, but device-trust controls block further access and no customer data is confirmed stolen.
  • ShinyHunters' claimed exfiltration window against McKesson ends (Aug 21-25, ~1TB / 284 million records); the group issues a $55,236,150 ransom demand with a 72-hour deadline.
  • McKesson discovers the cybersecurity incident and activates its incident response protocols.
  • McKesson publicly discloses the incident; BleepingComputer, CyberInsider, and DataBreaches.net report ShinyHunters' claims and the 284-million-record figure, with McKesson stating the investigation is in early stages and no material impact has yet been determined.
  • The 72-hour ransom deadline lapses; McKesson has not responded to or negotiated with ShinyHunters.

Sources cited for ShinyHunters Extortion Group Claims 284M-Record McKesson

More in data breach

Detection coverage for TL-2026-2208

As of 2026-08-29, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2208 across Splunk SPL, Microsoft KQL and Sigma, covering 12 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats