Quick Summary
AllegedExecutive Summary
shinyhunters listed McKesson Corporation, a US-based healthcare company operating at mckesson[.]com, as an alleged victim on 2026-08-30, claiming unauthorized access to the company’s systems and data. Healthcare is one of shinyhunters’ core target sectors, making this claim consistent with the group’s known pattern. The claim hasn’t been independently verified. shinyhunters listed 24 victims over the past 60 days, concentrating in US, IL, and CH with sector focus on Technology and Healthcare. McKesson’s healthcare profile in the US fits squarely within the group’s established targeting pattern.
Technical Analysis
SOCRadar CTI’s stealer-log analysis returned a **severe_exposure_in_sample** verdict for McKesson Corporation. Infostealer telemetry flagged 12 employee credentials on fedsvc, portal.mms, and mms systems plus 1 external and 7 corporate third-party credentials — a mix of internal and external exposure. Credential timestamps span 2024-03-21 to 2026-08-28, suggesting sustained pre-attack access spanning more than two years.
Disclaimer
This report is intended for threat intelligence and security awareness purposes. SOCRadar does not host, redistribute or buy stolen data. All breach information reported here is collected from publicly accessible threat actor and ransomware portals. This content is intended to equip CTI teams with context around recent attacks. While we strive for accuracy, listings on ransomware leak and extortion sites cannot always be independently verified and may not reflect confirmed breaches. If you believe any data in this report is incorrect, please contact us.