Tendvane

← All articles

SecurityAugust 29, 2026

A company you have never dealt with may hold your prescription history

McKesson is not a name that appears on your receipt, but it moves roughly a third of the medicines in North America and runs software that pharmacies and clinics use every day. That is why a breach there reaches so far past its own customers.

The company disclosed on 28 August, in a filing with the SEC, that someone gained unauthorised access to third-party applications it uses and took data. The extortion group ShinyHunters claims 284 million records, lifted between 21 and 25 August from McKesson's Salesforce and Snowflake environments. Records are not people, and how many individuals are affected is still unknown. The sample the group showed reporters at CyberInsider matched the claim, though: names, addresses, dates of birth, Social Security numbers, patient IDs, medications, allergies, appointment details and physician records. McKesson found the intrusion on 25 August and brought in outside specialists. ShinyHunters says it demanded about $55 million and never got an answer.

How they got in deserves more attention than any of the technical detail. It was a phone call. The group says it voice-phished two employees out of their sign-in details, then walked into the cloud services those accounts unlocked. No exotic malware, no unpatched software. The oldest trick there is, on a very large stage.

Nothing here needs a password reset, because your password was not in the pile. What comes next is quieter and harder: medical detail makes a scam sound like it genuinely came from your pharmacy. Treat any call or message that quotes your prescriptions as unproven until you ring the number printed on the packaging yourself. If you have never taken stock of which accounts and sign-ins your PC is wired into, Tendvane's Privacy and accounts check puts that list in one place.

Sources

Download Tendvane