P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

Breaches and Incidents

ShinyHunters claims 284 million McKesson records. It is a row count, and the units McKesson named are 14.9% of the business

McKesson confirmed a breach discovered on 25 August and, four days later, confined it to a subset of customers in two business units that make up 14.9% of its revenue. The 284 million figure is an attacker claim about rows, not people, and both outlets that spoke to the group have corrected it. As a count of individuals it would be roughly 83% of the United States.

By Parminder Kumar Sharma · · 8 min read

A long blank unprinted paper roll coiling away into darkness, captioned: 284 million records, not 284 million people. 14.9% of revenue, in the units named.

What McKesson has actually said

Three documents, and they are short enough to read in full rather than in summary.

The Form 8-K filed on 28 August 2026 discloses an incident discovered on 25 August. It is filed under Item 7.01, Regulation FD Disclosure, which matters and is covered below. Its operative sentence is:

As of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations.

The customer notice of 28 August confirms "unauthorized access and exfiltration of data" involving "third-party applications". The update of 29 August is the one that does the real work, and it landed after most of the coverage was written:

we've confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units

McKesson has also committed to credit monitoring for "partners, customers and their patients whose data was exfiltrated". So exfiltration is confirmed, patient data is confirmed by implication, and the scope is confirmed as a subset of customers inside two named business units.

McKesson has confirmed no record count, no individual count, no attacker, and no attack method. It has never named Salesforce, Snowflake, Okta, vishing, or ShinyHunters.

The 284 million is a row count, and the attackers said so

The figure travelling under this story is 284 million, and a good deal of the early coverage attached the word patients to it. The two outlets that actually spoke to the group both went back and corrected that.

BleepingComputer printed the clarification as a correction: the figure is "a raw count of approximately 284 million data records, or lines, rather than a count of unique individuals", and added plainly that this "does not mean that the breach impacted 284 million patients". CyberInsider appended its own version: 284 million records "linked to tens of millions of patients, but the exact number of people in the breach is not yet known".

That last part is worth pausing on. The attackers do not know how many people are in the data. Nobody has counted anything.

Two tests using only first-party numbers show why the people reading cannot be right.

Testing 284 million against McKesson's own numbers

TESTING 284 MILLION AGAINST McKESSON’S OWN NUMBERSTwo tests, using only first-party published data. The figure fails both as a count of people.TEST 1 · IF THE 284 MILLION WERE PEOPLE284,000,00082.8% of everyone in the United Statesthe whole bar is the US population, about 343 millionFive of every six people in the country, newborns included, from one distributor’s third-party applications.TEST 2 · THE UNITS McKESSON CONFIRMED AS AFFECTED, BY REVENUE83.4%12%North American Pharmaceutical, not among the affected units14.9%Oncology and Multispecialty, plus Medical-SurgicalAnd within those two, McKesson says the incident touched “a subset of customers”, not all of them.The attackers have already conceded the point.They told reporters the figure is a raw count of records, not individuals, and that they do not yetknow how many people are in the data. No count has been confirmed by McKesson or any regulator.Population from US Census Bureau vintage 2025 estimates. Segment revenue from McKesson’s FY2026 Exhibit 99.1. Scope fromMcKesson’s customer notice of 29 August 2026. The two bars share a width, not a denominator.
Neither bar is evidence about the other; each is drawn against its own stated denominator, which is why both are labelled. The point is narrow and it holds: nothing McKesson has published supports a reading of 284 million as individuals, and the only parties who have described the figure at all say it counts rows.
Neither bar is evidence about the other. Each is drawn against its own stated denominator, and both denominators are published by first parties.

Test one. The United States resident population in 2026 is roughly 343 million, per US Census Bureau vintage 2025 estimates. If 284 million were people, this single incident would cover about 82.8% of the country, newborns included.

Test two. McKesson's own FY2026 segment reporting puts North American Pharmaceutical at 83.4% of revenue. The two units it has named, Oncology and Multispecialty at 12.0% and Medical-Surgical at 2.9%, are 14.9% between them. And within those two, McKesson says a subset of customers.

Healthcare data warehouses hold many rows per person: one per prescription, per claim, per shipment, per appointment. McKesson's own marketing makes the same distinction without meaning to, describing CoverMyMeds as enabling access to medications "more than 100 million times each year". Times, not people.

None of this means the breach is small. It means the number in the headline is not a number of victims, and nobody currently knows what that number is.

Almost everything else you have read is one source

This is the part worth internalising, because the shape recurs.

Who is the source for each element of this story

ElementStatusSource
Incident discovered 25 August 2026ConfirmedMcKesson, SEC Form 8-K
Unauthorised access to third-party applicationsConfirmedMcKesson, 8-K and notices
Data was exfiltratedConfirmedMcKesson, 28 August notice
Scope is two named business unitsConfirmedMcKesson, 29 August notice
Vishing against employeesClaim onlyShinyHunters, via BleepingComputer
Okta single sign-on compromiseClaim onlyShinyHunters, via BleepingComputer
Salesforce and Snowflake accessClaim onlyShinyHunters, via BleepingComputer
284 million recordsClaim onlyShinyHunters, via BleepingComputer
About 1TB over 21 to 25 AugustClaim onlyShinyHunters, via BleepingComputer
Ransom of $55,236,150 on a 72-hour deadlineClaim onlyShinyHunters, via BleepingComputer
Compiled from McKesson's SEC filing and customer notices, and from BleepingComputer's reporting of its direct contact with the group, 28 August 2026.

Every technical detail of the intrusion, and every number, comes from one interested party speaking to journalists. No sample of the data has been published or independently examined. There is no proof of possession in the public record at all.

That is not an argument that the claims are false. ShinyHunters has a documented history with exactly this pattern, against Snowflake customer environments in 2024 and Salesforce tenants via the Salesloft Drift OAuth token campaign in 2025, so the described chain is entirely plausible. It is an argument about what a reader is entitled to state as fact on a Monday morning.

The clocks, and why the SEC filing is not late

There has been some suggestion that the filing is thin or delayed. On the present record it is neither, and the reason is a detail worth knowing for your own incident response.

Item 1.05 of Form 8-K requires disclosure within four business days of the registrant determining that an incident is material. The clock does not run from discovery. McKesson has expressly stated it has made no such determination, so no Item 1.05 filing is currently due. What it filed instead is an Item 7.01 furnishing, which is voluntary, carries lighter liability than a filed disclosure, and satisfies Regulation FD alongside the public website notice. Three business days after discovery.

Whether the materiality determination is being deferred is a fair question. It is a judgement, and there is no public evidence either way.

What is due, and when

  1. 25 Aug 2026

    Incident discovered

    The date McKesson states in its 8-K. Every HIPAA clock in this story starts here.

  2. 28 Aug 2026

    Form 8-K furnished

    Item 7.01, three business days after discovery. Signed by the Chief Legal Officer. No materiality determination made.

  3. 29 Aug 2026

    Scope confirmed

    A subset of customers within Oncology and Multispecialty, and Medical-Surgical. Credit monitoring offered to affected patients.

  4. 24 Oct 2026

    HIPAA outer limit

    Sixty days from discovery: individual notice, notice to the HHS Secretary for 500 or more individuals, and media notice where more than 500 residents of a state are affected.

Dates from McKesson's SEC filing and customer notices. HIPAA deadlines calculated from the confirmed discovery date under 45 CFR 164.400 to 414.

We checked the HHS Office for Civil Rights breach portal directly on 30 August. There is no McKesson entry, and in fact no August 2026 submissions from anyone. That is expected and is not a finding: five days of a sixty-day window have elapsed and the portal lags submission. If you see the portal's silence reported as significant, it is being misread.

One genuine open question sits underneath all of this. McKesson is a business associate for much of its distribution and technology work and a covered entity in specific lines, and its own privacy notice hedges precisely: services are provided "to the extent that we are functioning as a HIPAA Covered Entity". Which capacity applies to the affected data decides who owes notice to whom. It is not yet public.

There is no patch here either

We checked the CISA KEV catalogue, version 2026.08.27 with 1,685 entries, for Snowflake, Okta, Salesforce, Salesloft and Drift. No matches. As with the TerminalFix chain published this morning, no software flaw is implicated in the reported chain. Vishing a help desk, using the credentials it gives you, and querying a data warehouse you now have legitimate access to are not vulnerabilities.

Take this with you

What this story should change in your programme

  • Assume the number you brief internally is wrong until a regulator or the company confirms it. Say records, not people, and attribute it to the attacker, because that is who said it.
  • Verify identity at the help desk with something that is not knowledge-based. The reported entry point is a phone call, and every control after it inherits that failure.
  • Enforce phishing-resistant MFA on the identity provider, not just on the applications behind it. A compromised single sign-on account is every downstream SaaS tenant at once.
  • Monitor and rate-limit bulk export from your data warehouse. A single query returning hundreds of millions of rows is an operational anomaly long before it is a security alert.
  • Inventory which of your SaaS tenants can be reached from one identity, and write down what the worst single-account compromise actually reaches.
  • If you are a covered entity whose data sits with a distributor or clearing house, establish now which capacity your business associate agreement puts them in, because that decides who notifies your patients.

The position

The interesting thing here is not the size of the breach, which nobody knows, but how quickly a row count became a population. It took roughly a day for "284 million records" to be reported as "284 million patients", and the correction is now travelling more slowly than the error, partly because a URL slug fossilised the first version.

This site has run the same shape repeatedly this month: a Shadowserver count of vulnerable IP addresses read as compromised organisations, a newspaper headline figure absent from the underlying research. The failure is never fabrication. It is a denominator going missing in transit.

McKesson, for its part, has behaved reasonably on the visible record: it disclosed in three business days without being obliged to, and it narrowed the scope publicly four days after discovery. The thing to watch is not the 8-K. It is 24 October, and what the notification says when it arrives.

Sources

  1. PrimaryForm 8-K, Items 7.01 and 9.01, event dated 25 August 2026, filed 28 August 2026McKesson Corporation via SEC EDGARaccessed 2026-08-30
  2. PrimaryCustomer Cybersecurity Information Center, notices of 28 and 29 August 2026McKesson Corporationaccessed 2026-08-30
  3. PrimaryExhibit 99.1, FY2026 fourth quarter and full year results, segment revenuesMcKesson Corporation via SEC EDGARaccessed 2026-08-30
  4. PrimaryBreach Notification Rule, 45 CFR 164.400 to 414, the sixty-day limitsUS Department of Health and Human Servicesaccessed 2026-08-30
  5. PrimaryBreach portal, searched 30 August 2026: no McKesson entry and no August 2026 submissionsHHS Office for Civil Rightsaccessed 2026-08-30
  6. PrimaryMonthly national population estimates, vintage 2025: 2026 values of 342.3 to 343.0 millionUS Census Bureauaccessed 2026-08-30
  7. PrimaryKnown Exploited Vulnerabilities catalogue, version 2026.08.27: no Snowflake, Okta, Salesforce, Salesloft or Drift entriesCISAaccessed 2026-08-30
  8. Reported byMcKesson discloses breach after ShinyHunters claims patient data theft, 28 August 2026, including the records-not-individuals correctionBleepingComputeraccessed 2026-08-30
  9. Reported byShinyHunters claims McKesson data breach exposing 284 million patient records, 28 August 2026CyberInsideraccessed 2026-08-30

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.