Lead story
ShinyHunters Claims 284 Million McKesson Records — and the Clock Is Already Ticking
Healthcare and pharmaceutical logistics giant McKesson has confirmed a cyberattack on its systems, with the notorious ShinyHunters extortion group claiming it swiped 284 million records and threatening to publish everything if a ransom isn't paid. The company has brought in outside investigators and told regulators it's still in the early stages of understanding the damage — which, at this scale, could take a while.
McKesson is not a household name to most people, but it is the circulatory system of US healthcare. The company moves roughly one-third of all pharmaceuticals distributed in the United States and supplies hospitals, pharmacies, and healthcare networks across North America and beyond. A breach of this magnitude doesn't just mean leaked email addresses — it potentially means patient data, prescription records, and supply chain intelligence sitting in criminal hands.
ShinyHunters' track record makes this credible. The group has previously claimed and delivered on large-scale data thefts from Ticketmaster, Santander Bank, and dozens of others. Their method is typically to post a sample, set a deadline, and follow through on publication if payment isn't made. McKesson has not confirmed exactly what data was taken or whether it originated from a third-party application — the company's own filing describes "an unnamed third-party application" as the entry point, which raises its own questions about supply chain risk management.
The timing is awkward. McKesson is currently warning of "service degradation," which suggests operational impact beyond just data exfiltration. Healthcare logistics disruption ripples fast — delayed pharmaceutical deliveries are a patient safety issue, not just a business continuity problem.
For Australian readers, the parallel risk is real. McKesson has distribution operations in Australia through its Australian Healthcare Solutions arm, and a number of Australian hospital networks and pharmacy groups are part of global pharmaceutical supply chains that intersect with companies like McKesson. The SOCI Act's third-party risk requirements exist precisely for scenarios like this — a critical infrastructure provider compromised via an upstream software dependency. If your organisation has any supply chain exposure to McKesson or its technology partners, now is the time to ask questions.
The attacker's deadline is not yet publicly confirmed, but ShinyHunters historically moves quickly. Defenders in adjacent industries — anyone in pharma logistics, hospital networks, or healthcare IT — should be monitoring for data dumps and preparing customer notification playbooks.
What to watch: whether McKesson identifies the breached third-party application (which would tell us a great deal about the attack surface), whether data actually appears online when the deadline hits, and whether US regulators treat this as a HIPAA mass-notification event. A 284-million-record claim from a group with ShinyHunters' batting average deserves to be treated as credible until proven otherwise.
