Home › Intelligence › Brief
BREACH BRIEF🟠 High Breach

McKesson Breach: ShinyHunters Claims Theft of 284 Million Patient Records via Voice‑Phishing Attack

McKesson disclosed a breach after the ShinyHunters group claimed to have stolen 284 million patient records through a voice‑phishing campaign. The incident highlights gaps in access‑control and employee awareness that SOC 2 programs are designed to address.

LiveThreat™ Intelligence · 📅 August 29, 2026· 📰 bleepingcomputer.com
🟠
Severity
High
BR
Type
Breach
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
3 recommended
📰
Source
bleepingcomputer.com

McKesson Breach: ShinyHunters Claims Theft of 284 Million Patient Records via Voice‑Phishing Attack

What Happened — An extortion group calling itself ShinyHunters says it accessed third‑party applications used by McKesson and exfiltrated 284 million patient records. The attackers reportedly used vishing (voice‑phishing) social‑engineering calls to compromise employee credentials. McKesson disclosed the incident in a Form 8‑K filing and has activated its incident‑response plan.

Why It Matters for Compliance & Audit Readiness

  • This is a textbook SOC 2 CC 6.2 scenario: unauthorized access to systems handling PHI, highlighting the need for documented access‑control policies and continuous monitoring.
  • Evidence of a successful phishing campaign underscores the importance of a formal Security Awareness Training program that can be audited as part of your SOC 2 readiness.
  • The breach of third‑party applications triggers vendor‑management controls (CC 9.1) and requires auditable proof that due‑diligence and continuous monitoring were in place.

Who Is Affected – Healthcare providers, pharmacies, and any organization that relies on McKesson’s distribution platform; broadly the U.S. health‑care ecosystem.

Recommended Actions

  • Map the incident to SOC 2 CC 6.2 (Logical Access) and CC 9.1 (Vendor Management) controls; collect logs, access‑review evidence, and third‑party contracts as audit artifacts.
  • Initiate a targeted Security Awareness Training refresh focused on vishing detection and credential protection; document completion for audit trails.
  • Conduct a third‑party risk reassessment of any applications integrated with McKesson’s ecosystem, and implement continuous monitoring of those connections.

Source: BleepingComputer

Technical Notes – Attack vector: voice‑phishing (vishing) social engineering; compromised third‑party applications (specific apps not disclosed); data exfiltrated includes patient identifiers, treatment records, and prescription history. Source: same as above

📰 Original Source
https://www.bleepingcomputer.com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Security Awareness

Awareness is a control you can evidence too.

Verisq AI Trust Operations records training completion and policy adoption as audit evidence — turning 'we train our staff' into something you can actually prove.

See how Verisq AI Trust Operations covers awareness →