ShinyHunters has added McKesson Corporation, Neogen Corporation, Jack Henry & Associates and Elekta AB to its growing list of alleged victims, giving the companies until Sept. 1 to engage before the group threatens to publish stolen data and cause additional disruption.
The latest claims continue a string of aggressive extortion posts from ShinyHunters, which has increasingly used public deadlines and threats of further “digital” problems to pressure alleged victims into negotiations.
Of the 4 new claims, McKesson carries the most specific allegation. ShinyHunters claims it compromised hundreds of millions of records or database rows containing sensitive information ranging from personally identifiable information to protected health information.
The group has not provided similarly detailed descriptions of the data allegedly obtained from Neogen, Jack Henry or Elekta.
McKesson claim includes alleged PII and PHI theft
ShinyHunters claims to have compromised hundreds of millions of records associated with McKesson Corporation, one of the largest healthcare companies in the United States.
The group alleges the data includes both personally identifiable information and protected health information, although it has not publicly established how many unique individuals are represented by the claimed record count or provided sufficient evidence to independently verify the scale of the alleged theft.
ShinyHunters is attempting to pressure McKesson into negotiations by threatening full publication of the allegedly stolen information if the company does not engage.
The group has set a Sept. 1 deadline and also threatens unspecified additional digital problems if its demands are ignored.
McKesson had not issued any public statement confirming ShinyHunters’ claims at time of publication.
Jack Henry adds financial sector exposure
ShinyHunters has also named Jack Henry & Associates, a major financial technology provider whose products and services are used by banks and credit unions.
Unlike its McKesson post, the group has not publicly described what information it allegedly obtained from Jack Henry. Instead, ShinyHunters issued the same Sept. 1 ultimatum threatening publication and additional digital disruption if the company does not engage.
The potential significance of the claim is heightened by Jack Henry’s position within the financial sector. The company provides core processing, digital banking, payments and other technology to financial institutions, making the nature and origin of any alleged compromise particularly important.
ShinyHunters has not provided evidence establishing that customer financial institutions or their data were affected.
Jack Henry & Associates had not issued any public statement confirming the ShinyHunters claim at time of publication.
Elekta and Neogen receive same ultimatum
Swedish medical technology company Elekta AB is another of the newly named organizations. Elekta develops precision radiation medicine and radiotherapy technology used by healthcare providers around the world.
ShinyHunters has not disclosed what data it allegedly obtained from Elekta or how the company was purportedly compromised. The group instead issued the same final warning demanding contact by Sept. 1.
Neogen Corporation, a Michigan-based company specializing in food and animal safety products and services, was also added to the group’s victim list. Its listing was updated Aug. 30 and similarly provides no description of the allegedly compromised data.
The lack of technical details or data descriptions for the Neogen, Jack Henry and Elekta claims makes it impossible to independently assess the scope of any alleged compromise from the listings alone.
Neogen and Elekta had not issued public statements confirming the ShinyHunters claims at time of publication.
Sept. 1 deadline applied across multiple victims
All 4 companies have been given the same Sept. 1 deadline, suggesting ShinyHunters is coordinating its latest extortion push across multiple alleged victims rather than negotiating each claim on an entirely separate public timeline.
The group threatens to leak data if the organizations fail to engage and has also warned of unspecified digital problems. ShinyHunters does not explain what those additional actions would involve.
The language represents an escalation beyond a simple threat to publish stolen information, although there is currently no evidence establishing that the group has carried out additional disruptive attacks against these 4 organizations.
The latest additions expand an already active ShinyHunters campaign. BreachNews has recently tracked the group as it added organizations including ReliaQuest and CyrusOne, followed by Logitech and Streamlabs and BOK Financial and NovoCure.
The group’s broader activity and previous claims are tracked in the BreachNews ShinyHunters threat actor profile.
BreachNews will update this report if any of the companies confirm an incident, ShinyHunters publishes additional evidence, or the group carries out its threatened Sept. 1 data releases.











