September 1, 2026 284 Million Records Claimed at the Supplier: What the McKesson Breach Means for Your Dental Practice
On August 25, 2026, McKesson Corporation – one of the largest healthcare companies on the continent, distributing pharmaceuticals and medical supplies and running health-information-technology and care-management platforms – discovered a cybersecurity incident. In its disclosure, McKesson says the incident involved unauthorized access to certain third-party applications and the exfiltration of data, so far associated with a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units. The investigation is early, and the company has not yet confirmed the amount or nature of the data taken. Then the other shoe: the extortion group ShinyHunters claimed the attack and, on its leak site, claims to have stolen roughly 284 million records. A Canadian dental practice is nowhere near the centre of that story – but the way this breach happened is a blueprint that fits your office exactly.

What is confirmed, and what is only claimed
It is worth being disciplined about the numbers, because the headline figure is not McKesson’s. What the company has confirmed is a breach, unauthorized access to third-party applications, some data exfiltration, and an affected subset of two specific business units. What ShinyHunters claims – and it is a claim, from a group whose business is extortion – is around 284 million records spanning personal and protected health information, which the group itself concedes does not mean 284 million unique patients. If it holds up, it would rank among the largest healthcare data thefts ever recorded. Treat the confirmed facts as facts and the leak-site boast as an unverified allegation, and you will read this story more clearly than most of the headlines about it.
The confirmed business units – oncology, multispecialty, and medical-surgical distribution – are not dental. So to be plain: there is no indication that dental patient records were part of this, and this article is not claiming otherwise. Its value is elsewhere – in how the attackers got in, because that method is coming for practices of every size and specialty.
The part a dental office should study: a phone call, not a zero-day
Strip away the scale and the interesting thing about this breach is how ordinary the entry was. According to ShinyHunters’ own account to BleepingComputer, the group did not defeat some exotic defence. It ran voice-phishing – vishing – calls against multiple employees, talked its way to compromised Okta single sign-on accounts, and then used that stolen identity to reach into Salesforce and Snowflake and pull data out. The group claims to have removed roughly 1 TB between August 21 and 25. No malware headline, no unpatched appliance – a human on the phone, a captured login, and two cloud applications that trusted it.

That chain – person → single sign-on → cloud app – is the whole lesson, and it is the same playbook ShinyHunters has run against a long list of organizations. It is also almost exactly the technique we described when voice phishing cracked a healthcare giant’s Microsoft login: convince a person, capture the identity, and the identity opens the doors. And ShinyHunters is the same crew behind the Medtronic breach we covered earlier this year – this is a repeat performer with a proven method, not a one-off.
Why your practice is in scope for the same technique
Here is the uncomfortable translation. A modern dental practice no longer keeps everything on a server in the back room. Your practice-management software may be cloud-hosted; your email and files live in Microsoft 365; your imaging, your patient communications, your online booking, and your payroll are very likely separate cloud apps. And to keep staff sane, most of those are unlocked by a small handful of identities – often a single Microsoft or Google sign-in per person. That is exactly the shape of target ShinyHunters just exploited: not a network to breach, but an identity to borrow.
The attacker does not need to be sophisticated about your firewall if they can get one staff member on the phone, spin a believable story – “I’m from your IT provider, we’re seeing an issue with your account” – and walk away with a login. Once inside as a trusted user, they do not look like an intruder; they look like your receptionist. The scale of McKesson’s cloud footprint made the haul enormous, but the technique scales down to a six-operatory office just as cleanly.

The near-term risk: your patients are about to get scam calls
Even setting your own network aside, a breach of this size creates a downstream problem that lands on your front desk. When identity information and healthcare details are combined and sold or leaked, they become fuel for convincing impersonation scams. Criminals pose as a pharmacy, an insurer, a provider’s office, a debt collector, or a patient-support line, and use real personal details to make the approach sound legitimate – a supposed prescription problem, an unpaid claim, a delivery issue, an appointment change, or a request to “verify” insurance information. The health context is what makes it work; it manufactures urgency.
Your patients will not parse which company was breached. Some will receive these calls, and a few will phone your office confused, or worse, will be primed to hand over information to the next caller who claims to be from your practice. Your team should know that a wave of health-themed scam calls is a predictable aftershock of any large breach, and should never treat inbound callers as automatically trustworthy – a caller who “already knows” a patient’s details has proven nothing. This is also a reminder of what a breach actually costs when it is your own name on the notice.
What a dental practice should do about it
None of the defences here are exotic; they are the unglamorous fundamentals of protecting an identity-and-cloud practice. Make sure someone – your team or your IT provider – can confirm these five things:
- Inventory your cloud apps and the identities that unlock them. List every SaaS application the practice uses – practice management, Microsoft 365, imaging, communications, booking, payroll – and note which login unlocks each. You cannot protect a stack you have never mapped, and single sign-on means one compromised identity may open several of these at once.
- Move to phishing-resistant MFA. Text-message and app-tap codes can be phished or talked out of a user in real time. Passkeys or FIDO2 hardware keys cannot be handed over on a phone call, which is precisely the attack that worked here. Prioritize the accounts that unlock the most.
- Train staff – and the front desk – to resist vishing. The breach started with a phone call. Teach the team that no legitimate IT provider or vendor will ever ask them to read out a code, approve a prompt, or surrender a login over the phone, and give them a no-blame way to hang up and call back on a known number to verify.
- Watch for anomalous access to your cloud data. Ask whether your Microsoft 365 and other cloud platforms alert on unusual sign-ins and bulk data exports. The theft here was a large, quiet data pull by a “trusted” account – the kind of thing that is invisible unless someone is watching for it.
- Prepare a patient-facing response now. Draft a short, calm script for the front desk about breach-related scam calls, and a reminder that your practice will never phone a patient to demand payment or verify sensitive details out of the blue. Preparing the message before you need it beats improvising during a rush of confused calls.

The through-line of the McKesson story is not the eye-watering number ShinyHunters is advertising. It is that a company of that size was reached the same way a small office can be reached: a person, a stolen sign-in, and the cloud applications that trusted it. The record count is what makes the news; the method is what should make you check your own logins.

If you are not certain how many cloud applications your practice depends on, which identities unlock them, or whether those logins would survive a convincing phone call, contact Compudent Systems. We help dental practices across Ontario inventory their SaaS and single sign-on footprint, move the accounts that matter onto phishing-resistant MFA, train staff and front-desk teams to shut down vishing, and put monitoring in place so a quiet data pull from a cloud app does not go unnoticed – closing the exact door this breach walked through.
Sources & further reading:
- McKesson confirms cyber incident after ShinyHunters claims patient-data theft – Malwarebytes
- Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson – TechCrunch
- McKesson discloses breach after ShinyHunters claims patient data theft – BleepingComputer
Related Reading
- The FBI Just Refreshed Its Medusa Ransomware Warning for Healthcare: The Real Lesson for Your Dental Practice
- Ransomware Is Now a Patient-Safety Issue: What a 38% Hospital Mortality Study Means for Your Dental Practice
- Two Dental Groups on Leak Sites in One Week: What It Means When Your Practice’s Name Appears on a Ransomware Blog