InfoSec News Nuggets – 09/01/2026
Brief
McKesson Discloses Breach After ShinyHunters Claims Patient Data Theft
Healthcare and pharmaceutical distribution giant McKesson has confirmed a cybersecurity incident involving unauthorized access to third-party applications after the ShinyHunters extortion group claimed it stole roughly 284 million patient-related data records.
McKesson says it discovered the intrusion on August 25 and that its investigation is still in its early stages, while the attackers claim they used vishing calls against employees to compromise Okta single sign-on accounts and pivot into Salesforce and Snowflake environments, demanding over $55 million after McKesson allegedly failed to respond.
