All ransomware incidents
M
Ransomware group shinyhunters hits McKesson Corporation
McKesson Corporation — a healthcare target operating in US has been listed by the shinyhunters ransomware group on 2026-08-28. The information below reflects what the threat actor has publicly claimed on their leak site; the details have not been independently verified.
Incident Report
| Target Organization | McKesson Corporation |
|---|---|
| Threat Group | shinyhunters |
| Summary | Hundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI. We urge you to reach out. Read our emails. We will provide a substanial discount. Failure to engage with us will result in the full publication of data taken from you and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING |
| Date of Breach | 2026-08-28 |
| Discovery Date | 2026-08-28 |
| Region | US |
| Target Domain | — |
| Business Sector | Healthcare |
| Severity | MEDIUM |
Claim by shinyhunters
Hundreds of millions of records/rows of data was compromised containing very sensitive information spanning from PII to PHI. We urge you to reach out. Read our emails. We will provide a substanial discount. Failure to engage with us will result in the full publication of data taken from you and we very much intend to carry that out if you do not engage with us. This is a final warning to reach out by 1 Sep 2026 before we leak along with several annoying (digital) problems that'll come your way. Make the right decision, don't be the next headline. | Updated: 29 Aug 2026 | Warning: FINAL WARNING
Posted by the shinyhunters threat actor on its public leak site. This is the group's own statement and has not been independently verified by HackerFeeds.
Disclaimer
HackerFeeds does not engage in the exfiltration, downloading, taking, hosting, viewing, reposting, or disclosure of any stolen information. All breach data reported here is sourced from publicly available threat intelligence feeds for awareness purposes only.

