284 Million Health Records Stolen From the Company Behind Your Pharmacy
Hackers claim to have stolen 284 million patient records from McKesson, a healthcare giant most people have never heard of but whose systems touch almost every American prescription.
The Company You've Never Heard of Just Exposed Your Medical History
You don't know McKesson. You've never seen their logo in a pharmacy window or clicked their app. But the moment a pharmacist handed you a prescription, McKesson was probably in the room. They distribute drugs and medical supplies to pharmacies, hospitals, and clinics across the United States. They are invisible infrastructure. And on August 25, 2026, they confirmed a cybersecurity breach that may have put the most sensitive data about your health in the hands of criminals.
The hacking group ShinyHunters claims to have taken roughly 284 million patient-related records. Not 284 million unique individuals, necessarily. But 284 million rows of data, each tied to real people, real diagnoses, real medications.
How Did Attackers Get In?
They called McKesson employees on the phone. ShinyHunters used a technique called vishing, voice phishing, where attackers impersonate IT support or vendors and talk employees into handing over their login credentials. Once they had those credentials, they hijacked McKesson's Okta accounts. Okta is single sign-on software. One password, one token, many systems. Attackers used that access to reach McKesson's Salesforce and Snowflake cloud environments, where patient data lived. Over four days, August 21 through 25, they pulled out approximately one terabyte of data before McKesson detected the intrusion.
There was no sophisticated zero-day exploit. No nation-state malware. A phone call. That's the entry point.
What Was Actually Stolen?
ShinyHunters claims the haul includes names, Social Security numbers, dates of birth, medical record numbers, Medicaid numbers, prescription and medication records, diagnoses, and appointment data. McKesson confirmed the incident via an SEC filing after the breach was detected on August 25.
ShinyHunters then sent McKesson a ransom demand: $55,236,150, payable within 72 hours. McKesson did not respond.
That means the data is almost certainly circulating now, or soon will be.
Why This Is Worse Than a Password Breach
You can change a password in 30 seconds. You can cancel a credit card in five minutes. You can freeze your credit for free. None of that works here.
Your diagnosis of diabetes, depression, or a chronic condition does not reset. Your medication history does not reset. Those facts are permanent, and they follow you. Insurance companies use that kind of information to assess risk. Scammers use it to impersonate healthcare providers and extract money or additional data from vulnerable people. A stolen SSN combined with a full prescription history is a remarkably complete profile for committing fraud in your name.
This is why health data breaches live in a different category of harm. The exposure doesn't expire.
What You Should Do Right Now
-
Freeze your credit at all three bureaus. Equifax, Experian, and TransUnion all offer free credit freezes. Do it today. A freeze blocks anyone from opening new credit in your name without your explicit approval. It takes about five minutes per bureau.
-
Place a fraud alert. A fraud alert tells lenders to take extra steps to verify your identity before extending credit. Placing one with a single bureau triggers notification to the other two automatically.
-
Review your explanation of benefits. If you have health insurance, check your EOB statements for services you didn't receive. Medical identity theft often surfaces as claims for procedures or prescriptions you never had.
-
Watch for targeted phishing. Attackers who have your name, SSN, and medication history will use it to craft convincing scam calls and emails. If someone contacts you claiming to be a pharmacy, insurer, or Medicare representative, hang up and call back using a number you look up yourself.
-
Enable multi-factor authentication on health portals. Your health insurer's portal, pharmacy apps, and patient records systems all deserve a second factor. Use an authenticator app, not SMS, when possible.
-
Check for breach notification from McKesson. Companies that suffer breaches of this scale often carry legal obligations to notify affected individuals. Watch for official communications and follow the credit monitoring instructions they contain.
-
Check what you already have. Many credit cards and banks include identity monitoring for free. Look into what's already available to you before spending money on a paid service.
The Deeper Problem
The healthcare industry stores an enormous amount of sensitive data across thousands of vendors, distributors, and cloud platforms. Many of those companies, like McKesson, operate entirely out of public view. You've consented to nothing. You don't know who holds your records. You have no ability to opt out of a supply chain that requires your data to function.
The attack itself required nothing more than a convincing phone call. One employee gave up a password. Okta connected that password to dozens of internal systems. A terabyte of medical records left McKesson's environment before anyone noticed.
The technology isn't broken. The assumption that employee training is a sufficient defense for data this sensitive is what's broken. Every organization that holds health records at scale is one vishing call away from this headline.
Do this now: Freeze your credit at all three bureaus, turn on multi-factor authentication for your insurance and pharmacy portals, and stay alert for unusually personal phishing attempts in the coming weeks. You can't undo what was taken. You can make yourself a harder target for what comes next.
Sources
Common Questions About Breach
What should I do immediately after a data breach?
Change your password for the affected account and any other account where you reused that password. Enable two-factor authentication. Monitor your bank and credit card statements. Place a free credit freeze at Equifax, Experian, and TransUnion. If your Social Security number was exposed, file an identity theft report at IdentityTheft.gov.
How long do companies have to notify me after a data breach?
In the US, notification timelines vary by state — typically 30 to 90 days after a breach is confirmed. Under GDPR in Europe, companies must notify regulators within 72 hours. Many states require individual notification "in the most expedient time possible." Companies often delay notification while investigating.
Should I freeze my credit after a data breach?
Yes. A credit freeze prevents new accounts being opened in your name without your explicit unfreeze. It is completely free at all three major bureaus, does not affect your credit score, and does not impact existing accounts. Unfreeze temporarily when you need to apply for credit, then refreeze immediately.
More in breach
Stay invisible. Follow @hack_decoded