zerofox logo
Threat Intelligence

Flash Report: ShinyHunters Continues Shift to Encryption-Less Data Theft

by ZeroFox Intelligence
Flash Report: ShinyHunters Continues Shift to Encryption-Less Data Theft
5 minute read

Key Findings

  • On September 10, 2026, threat actor group ShinyHunters leaked data from McKesson Corporation (McKesson) on its dark web leak site. The data allegedly came from an August 2026 breach of 6.4 million personally identifiable information (PII) records associated with McKesson.
  • Neither the public disclosures nor the ShinyHunters claim mentioned ransomware or encryption, making it very likely the group did not encrypt McKesson data; instead, ShinyHunters very likely extracted the data, issued a ransom demand, and then almost certainly leaked the data when the victim refused to pay.
  • ZeroFox assesses that the lack of encryption in the McKesson breach was almost certainly intentional and very likely represents a tactical shift by ShinyHunters from double extortion to encryption-less data theft.
  • The ShinyHunters data breach of McKesson and the subsequent release of sensitive data almost certainly reflect the continuation of the shift in the ransomware and digital extortion (R&DE) ecosystem from encryption-based attacks to “encryption optional” data extortion.

Details

On September 10, 2026, threat actor group ShinyHunters leaked data from McKesson on its dark web leak site. The data allegedly came from an August 2026 breach of 6.4 million PII records, including email addresses, dates of birth, employers, genders, names, personal health data, phone numbers, and physical addresses belonging to individuals identified as patients, marketing campaign participants, staff, and healthcare providers associated with McKesson1.

  • McKesson is a Texas-based healthcare logistics, pharmaceutical distribution, and health information technology company2.
  • McKesson discovered the breach on August 25, 2026, and reported the incident to the Securities and Exchange Commission three days later3
  • ShinyHunters claimed responsibility for the breach and stated it had stolen 1 TB of data over a four-day period.4

Neither the public disclosures nor the ShinyHunters claim mentioned ransomware or encryption, making it very likely the group did not encrypt McKesson data; instead, ShinyHunters very likely extracted the data, issued a ransom demand, and then almost certainly leaked the data when the victim refused to pay.

Notably, ShinyHunters is known to have encryption capability, as the group released the ShinySp1d3r encryptor in November 20255. ZeroFox assesses that the lack of encryption in the McKesson breach was almost certainly intentional and very likely represents a tactical shift by ShinyHunters from double extortion to encryption-less data theft.

Extortion without encryption is not a new tactic, but its use has grown significantly since late 2025. Europol stated that the extortion model “continues shifting from encrypting data to pressuring victims to pay for their data to not be released.”6 Additionally, the Federal Bureau of Investigation (FBI) has stated that threat actors extort “without relying on traditional ransomware encryption.”7

In recent years, observable ransoms paid by encryption victims have been declining; blockchain analysis shows a traced ransom payment rate of 28 percent in 2025, compared to more than 78 percent in 2022. This reduction has very likely made the costly infrastructure required to run an encryption-based ransomware-as-a-service (RaaS) operation less profitable. 

  • Encryption has not declined, with more than 50 percent of R&DE incidents involving encryption. Thus, it is almost certain that encryption-less data extortion is an additional tactic rather than a substitutive one.

The strongest driver of the continuing shift to encryption-less extortion is almost certainly the collapse of any credible assurance that payment results in deletion and the possibility of threat actors retaining decrypted data after ransom payment and attempting re-extortion later. When the UK National Crime Agency (NCA) disrupted LockBit, the group retained data from previous victims who had paid—suggesting that, even when a ransom is paid, there is no guarantee a victim’s data will be deleted. 

The ShinyHunters data breach of McKesson and the subsequent release of sensitive data almost certainly reflect the continuation of the shift in the R&DE ecosystem from encryption-based attacks to “encryption optional” data extortion. While encryption will likely remain the most common attack for the remainder of 2026, the share of R&DE incidents involving encryption will very likely decrease over the next 12 months in favor of encryption-less data extortion.

Appendix A: Traffic Light Protocol for Information Dissemination

Appendix B: ZeroFox Intelligence Probability Scale 

All ZeroFox intelligence products leverage probabilistic assessment language in analytic judgments. Qualitative statements used in these judgments refer to associated probability ranges, which state the likelihood of occurrence of an event or development. Ranges are used to avoid a false impression of accuracy. This scale is a standard that aligns with how readers should interpret such terms.

  1. hXXps://haveibeenpwned[.]com/Breach/McKesson ↩︎
  2. hXXps://www.mckesson[.]com/about-us/
    ↩︎
  3. hXXps://www.sec[.]gov/Archives/edgar/data/927653/000092765326000247/mck-20260825.htm ↩︎
  4. hXXps://www.bleepingcomputer[.]com/news/security/mckesson-discloses-breach-after-shinyhunters-claims-patient-data-theft/ ↩︎
  5. hXXps://www.bleepingcomputer[.]com/news/security/meet-shinysp1d3r-new-ransomware-as-a-service-created-by-shinyhunters ↩︎
  6. hXXps://www.europol.europa[.]eu/cms/sites/default/files/documents/IOCTA-2026.pdf ↩︎
  7. hXXps://www.ic3[.]gov/CSA/2026/260526.pdf ↩︎

See ZeroFox in action