Skip to content
Tech News
← Back to articles

McKesson discloses breach after ShinyHunters claims patient data theft

read original more articles
Why This Matters

The McKesson data breach highlights the increasing risks faced by healthcare organizations from cyberattacks, especially those involving third-party applications. This incident underscores the importance for the healthcare industry and consumers to prioritize robust cybersecurity measures to protect sensitive patient data and maintain trust. As cyber threats evolve, continuous vigilance and improved security protocols are critical to safeguarding critical health information.

Key Takeaways

Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.

McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies.

CyberInsider first reported the breach earlier today, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission.

McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation remains in the early stages.

"Information about the incident, including any updates, is available on the company's website at www.mckesson.com/cybersecurity," McKesson said in its SEC filing.

"As of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations."

In a separate notice to customers, McKesson confirmed that the incident involved third-party applications and the unauthorized access and exfiltration of data.

"We take the security and privacy of our partners, customers and their patients very seriously. Upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to assist in our response," reads McKesson's notice.

The company said its investigation is ongoing to determine the full scope of the incident.

McKesson also warned that customers may experience intermittent service degradation believed to be related to the attack, although the company said it was not proactively disconnecting systems within its environment.

... continue reading