McKesson announced a cybersecurity incident that involved third-party programs and unauthorized access and data theft, while the company is still investigating the nature and extent of the incident and data theft.
HIPAA-covered entity, McKesson reported the occurrence on August 28, 2026. The company prompted an investigation of the cybersecurity incident involving the threat actor accessing third-party applications without authorization and exfiltrating data.
McKesson’s Securities and Exchange Commission filing states that it discovered the cybersecurity attack on August 25, 2026. McKesson started its incident response protocols and requested cybersecurity professionals to help with its response. Its cybersecurity staff and third-party specialists are looking into the unauthorized activity, finding out the scope of data theft, and working to lessen the impacts on system availability.
McKesson informed customers of the potential impact on system accessibility and business functions, which may include intermittent service degradation. The company mentioned it continued serving customers throughout its lines of business, taking orders, opening its distribution facilities, and delivering products within its distribution system.
Data Pertains to a Subset of Customers
According to the company’s early investigation findings, the incident affected data associated with a part of customers of McKesson’s Oncology & Multispecialty and Medical-Surgical business units. McKesson mentioned its preliminary actions succeeded in stopping further unauthorized access. However, the company has not confirmed if the incident is material or if it will materially impact its financial condition or outcomes of operations.
ShinyHunters Claims Theft of 284 Million Records
McKesson has not revealed the name of the group behind the attack. ShinyHunters listed McKesson on its data leak website and professed that it exfiltrated 284 million patient data records. The 284 million data pertains to rows of raw data instead of unique patients. The magnitude of the data theft is still being investigated by McKesson.
The ShinyHunters claims that the stolen data includes names, contact details, Social Security numbers, birth dates, health record numbers, Medicaid, medicine and allergy details, diagnoses, appointment details, and other sensitive information. The data reportedly pertains to McKesson’s Salesforce environment and Snowflake.
The reports state that roughly 1 terabyte of data was stolen from August 21 to August 25, 2026. The threat group issued a ransom demand of over $55 million. McKesson’s investigation continues to be focused on identifying the nature and extent of the unauthorized activity and the data theft.
McKesson Customer Operations
McKesson stated its customers need not do anything and that it is not proactively deactivating systems within its environment. The company continued taking orders and running its distribution centers after the incident. It continued shipping products through its distribution system.
The company’s investigation likewise includes finding out the impact of the incident on system availability and business operations.
Image credit: Dennis 428679009 Adobestock / logo©McKesson









