Skip to main content
McKessonCybersecurity incident

McKesson confirmed a cybersecurity incident affecting its systems following claims by threat actor ShinyHunters that voice-phishing two employees compromised up to 284 million patient records.

What happened

Post: "ShinyHunters Claims to have Voice-Phished 2 McKesson Employees and Extracted 284 Million Patient Records Including: Predictive health data, Identity, and..."

Source

Extracted from these lines

  • [comment u/AP123123123] One useful point of comparison is McKesson’s own SEC disclosure. It confirms a cybersecurity incident affecting its information systems, but says the company had not yet determined whether the financial or operational impact would be material.

reddit.com/r/cybersecurity/comments/1w1ffak/shinyhunters_claims_to_ha...Open the source

Comments on the post

5 of 30 comments
  • “Can THEY tell us what’s going on with Mitch?”

    u/Shakenbake8085 points · Aug 29, 2026View

  • “From the article: According to ShinyHunters , the allegedly stolen patient data includes: - Identity and contact information: full names, home addresses, dates of birth, phone numbers, email addresses, and Social Security numbers. - Healthcare identifiers: patient IDs, medical record numbers (MRNs), and Medicaid numbers. - Medical information: illnesses and diagnoses, allergies, medications, d”

    u/lead_oxide254 points · Aug 29, 2026View

  • “Why does a company that apparently does not treat patients have 284 million patient records with identities to lose? Also WHY is some of that predictive? More and more of these companies are being exposed for their shady fucked up data practices, usually when they lose the data. Then they just shrug and we get nothing”

    u/Poppybiscuit34 points · Aug 29, 2026View

  • “284 million records against a $55,236,150 ask comes out to about 19 cents per record. They priced it like a bulk liquidation.”

    u/Elouakili_Flexy21 points · Aug 29, 2026View

  • “Vishing is tough. User education important but what’s the best technical control for this? I could see Phishing resist authentication or Device compliance.”

    u/Jdruu17 points · Aug 29, 2026View

Extracted by Autobound

From the Signal API record
Signal
Cybersecurity incident

What this signalsUser posts often show product pain before it reaches reviews or churn.

Subreddit
r/cybersecurity
Stage
Confirmed
Event date
Aug 2026

The full record

From the Signal API record

Numbers

Mentions
5

Details

Timing
Completed
Category
Breach
Virality
High
Post kind
Link
Prominence
Core
Company's role
Subject
Signal category
Event

Topics and mentions

Topics

  • cybersecurity
  • data breach
  • healthcare
  • phishing

Flair

  • News - General

Extraction

Sentiment
Negative
Detected
Aug 29, 2026
signal_type
reddit-company
signal_subtype
cybersecurityIncident

Use this data

Get every Reddit signal for McKesson and the companies you sell to, in the tools you already use.

  1. Ask Claude about it

    Connect Autobound to Claude, Claude Code or Cursor with MCP. Then ask: “What changed at McKesson this week?”

  2. Send it to your own tools

    The Signal API returns Reddit signals for any list of companies as JSON, for your CRM, warehouse or app.

  3. Try it free

    Sign up and spend your free credits on the companies you sell to.

    Start Free1,000 free credits

The API returns more than this page shows

This page shows a preview. The full reddit-company record in the Signal API and MCP can also have these 8 fields. Some fields are empty for some signals.

Company

  • linkedin_urlValue in the API
  • industriesValue in the API
  • employee_count_lowValue in the API
  • employee_count_highValue in the API
  • revenueValue in the API
  • descriptionValue in the API

Signal

  • signal_nameValue in the API
  • associationValue in the API
Show the full JSONThe record on this page and the API request

GET /v1/signals/3dd3db46-0d6c-5438-aac2-048f4e60b2be returns this record as JSON. POST /v1/companies/enrich returns every signal for mckesson.com.

{
  "signal_id": "3dd3db46-0d6c-5438-aac2-048f4e60b2be",
  "signal_type": "reddit-company",
  "signal_subtype": "cybersecurityIncident",
  "detected_at": "2026-08-29T07:00:38+00:00",
  "company": {
    "name": "McKesson",
    "domain": "mckesson.com"
  },
  "data": {
    "nsfw": false,
    "stage": "confirmed",
    "awards": 0,
    "timing": "completed",
    "topics": [
      "cybersecurity",
      "data breach",
      "healthcare",
      "phishing"
    ],
    "post_id": "1w1ffak",
    "summary": "McKesson confirmed a cybersecurity incident affecting its systems following claims by threat actor ShinyHunters that voice-phishing two employees compromised up to 284 million patient records.",
    "category": "breach",
    "comments": [
      {
        "url": "https://www.reddit.com/r/cybersecurity/comments/1w1ffak/comment/p6kjgur/",
        "depth": 0,
        "score": 85,
        "author": "Shakenbake80",
        "excerpt": "Can THEY tell us what’s going on with Mitch?",
        "posted_at": "2026-08-29T07:44:41.000Z",
        "author_url": "https://www.reddit.com/user/Shakenbake80/"
      },
      {
        "url": "https://www.reddit.com/r/cybersecurity/comments/1w1ffak/comment/p6kekgy/",
        "depth": 0,
        "score": 54,
        "author": "lead_oxide2",
        "excerpt": "From the article:\n\n According to ShinyHunters\n\n , the allegedly stolen patient data includes:\n- Identity and contact information: full names, home addresses, dates of birth, phone numbers, email addresses, and Social Security numbers.\n- Healthcare identifiers: patient IDs, medical record numbers (MRNs), and Medicaid numbers.\n- Medical information: illnesses and diagnoses, allergies, medications, d",
        "posted_at": "2026-08-29T07:02:34.000Z",
        "author_url": "https://www.reddit.com/user/lead_oxide2/"
      },
      {
        "url": "https://www.reddit.com/r/cybersecurity/comments/1w1ffak/comment/p6locsg/",
        "depth": 0,
        "score": 34,
        "author": "Poppybiscuit",
        "excerpt": "Why does a company that apparently does not treat patients have 284 million patient records with identities to lose?\n\n Also WHY is some of that predictive? More and more of these companies are being exposed for their shady fucked up data practices, usually when they lose the data. Then they just shrug and we get nothing",
        "posted_at": "2026-08-29T12:56:48.000Z",
        "author_url": "https://www.reddit.com/user/Poppybiscuit/"
      },
      {
        "url": "https://www.reddit.com/r/cybersecurity/comments/1w1ffak/comment/p6km4fl/",
        "depth": 0,
        "score": 21,
        "author": "Elouakili_Flexy",
        "excerpt": "284 million records against a $55,236,150 ask comes out to about 19 cents per record. They priced it like a bulk liquidation.",
        "posted_at": "2026-08-29T08:08:03.000Z",
        "author_url": "https://www.reddit.com/user/Elouakili_Flexy/"
      },
      {
        "url": "https://www.reddit.com/r/cybersecurity/comments/1w1ffak/comment/p6lrsua/",
        "depth": 0,
        "score": 17,
        "author": "Jdruu",
        "excerpt": "Vishing is tough. User education important but what’s the best technical control for this?\n\n I could see Phishing resist authentication or Device compliance.",
        "posted_at": "2026-08-29T13:15:51.000Z",
        "author_url": "https://www.reddit.com/user/Jdruu/"
      },
      {
        "url": "https://www.reddit.com/r/cybersecurity/comments/1w1ffak/comment/p6to3wo/",
        "depth": 0,
        "score": 4,
        "author": "AP123123123",
        "excerpt": "One useful point of comparison is McKesson’s own SEC disclosure. It confirms a cybersecurity incident affecting its information systems, but says the company had not yet determined whether the financial or operational impact would be material. That is substantially narrower than the threat actor’s claim of 284 million records, so the gap between confirmed disclosure and alleged scope is worth watc",
        "posted_at": "2026-08-30T16:58:10.000Z",
        "author_url": "https://www.reddit.com/user/AP123123123/"
      },
      {
        "url": "https://www.reddit.com/r/cybersecurity/comments/1w1ffak/comment/p6lqi4r/",
        "depth": 0,
        "score": 3,
        "author": "Jeff-Hare-ERPRA",
        "excerpt": "That’s scary",
        "posted_at": "2026-08-29T13:08:46.000Z",
        "author_url": "https://www.reddit.com/user/Jeff-Hare-ERPRA/"
      },
      {
        "url": "https://www.reddit.com/r/cybersecurity/comments/1w1ffak/comment/p6wffvq/",
        "depth": 0,
        "score": 1,
        "author": "shrewdone_NY",
        "excerpt": "Sorry but I am not surprised! Between the information that people put on social media, access to voice\\video isn't hard to come by. Then its not hard to see how AI can create a \"problem\". Seems like investing in AI would be a downfall in a lot of cases especially for corporations that may already be struggling that then invest in technology that they don't fully understand. Or a bad actor invests",
        "posted_at": "2026-08-31T01:21:39.000Z",
        "author_url": "https://www.reddit.com/user/shrewdone_NY/"
      }
    ],
    "evidence": [
      "[post] ShinyHunters Claims to have Voice-Phished 2 McKesson Employees and Extracted 284 Million Patient Records Including: Predictive health data, Identity, and Healthcare Identifiers. McKesson Confirms Breach but not severity",
      "[comment u/AP123123123] One useful point of comparison is McKesson’s own SEC disclosure. It confirms a cybersecurity incident affecting its information systems, but says the company had not yet determined whether the financial or operational impact would be material."
    ],
    "link_url": "https://cyberinsider.com/mckesson-data-breach-exposing-284-million-patients/",
    "virality": "high",
    "post_date": "2026-08-29T07:00:38.000Z",
    "post_kind": "link",
    "sentiment": "negative",
    "subreddit": "cybersecurity",
    "event_date": "2026-08",
    "post_flair": [
      "News - General"
    ],
    "post_title": "ShinyHunters Claims to have Voice-Phished 2 McKesson Employees and Extracted 284 Million Patient Records Including: Predictive health data, Identity, and Healthcare Identifiers. McKesson Confirms Breach but not severity",
    "prominence": "core",
    "source_url": "https://www.reddit.com/r/cybersecurity/comments/1w1ffak/shinyhunters_claims_to_have_voicephished_2/",
    "entity_role": "subject",
    "post_author": "lead_oxide2",
    "upvote_ratio": 0.99,
    "mention_count": 5,
    "mention_surge": false,
    "subreddit_url": "https://www.reddit.com/r/cybersecurity/",
    "total_upvotes": 438,
    "comments_total": 35,
    "total_comments": 30,
    "post_author_url": "https://www.reddit.com/user/lead_oxide2/",
    "signal_category": "event",
    "comments_included": 10
  }
}

Long text fields are shortened on this page.

Looking up one signal by its id is free. Enrich costs 2 credits per signal returned; a call with no results is free.