McKesson's disclosure to customers and regulators

A young woman in a dark room surrounded by computers and cables, eating and typing on keyboards.

McKesson Corporation confirmed over the weekend that hackers exfiltrated customer data from its systems, disclosing the incident shortly after the ShinyHunters extortion group listed the company on its Tor-based leak site. In a filing with the U.S. Securities and Exchange Commission, the healthcare and pharmaceutical giant said it discovered "a cybersecurity incident affecting its information systems" on August 25, 2026. A Friday notice on McKesson's website said the event involved third-party applications and data theft, and the company noted it was not disconnecting any systems in response. On Saturday, McKesson said the unauthorized access had been disrupted and that services were not affected, and it committed to providing complimentary credit monitoring and identity protection services to impacted individuals.

Scope of the breach as confirmed by McKesson

The stolen data is tied to "a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units," according to McKesson's Saturday statement. In a separate notice to customers, the company's chief technology officer, Francisco Fraga, identified the same two business units as the source of the exfiltrated data. McKesson did not share details on the types of data involved, the number of affected people, or the identity of the attackers, and a spokesperson did not respond to a request for comment on Monday. The company delivers roughly one-third of prescription medicines to North American hospitals, pharmacies, and healthcare clinics, and also provides medical supplies, supports cancer treatment and specialty care, and operates the Health Mart pharmacy franchise.

ShinyHunters' claims of millions of patient records stolen

The ShinyHunters group told reporters it hacked McKesson's cloud environment by tricking several employees into granting access through phishing and social engineering. The hackers said they stole a range of personal information, including names, addresses, and Social Security numbers, alongside protected health information such as diagnoses, medications, allergies, and patient notes, and that the haul also included McKesson employee information such as home addresses. ShinyHunters claimed to have taken millions of rows of patient data from McKesson's cloud-hosted Snowflake and Salesforce environments but said it was unsure of the total number of individuals affected. The group also shared screenshots and a sample of the stolen data with TechCrunch, which verified a small subset against public records.

Ransom demand and extortion timeline

ShinyHunters has demanded a $55 million ransom from McKesson in exchange for not publicly releasing the stolen files, according to reporting from Bleeping Computer. The hacking group has claimed the theft of 284 million records from McKesson's systems. ShinyHunters is described as one of the most active data-extortion crews of the past two years, and McKesson is the latest healthcare company or medical device maker targeted in a string of recent cyberattacks aimed at stealing sensitive medical and health data for extortion.

Open questions and outstanding disclosures

McKesson has not publicly identified the attackers, specified the precise types of data compromised, or disclosed how many individuals are affected. The company has also not addressed the $55 million ransom demand publicly. McKesson's stock and operations have not been reported as disrupted, and the company has continued to serve customers while offering credit monitoring and identity protection to those impacted, though the eligibility criteria and rollout timing for those services remain unspecified in the available reporting.

Share this article

FacebookX

2 sources

Sources