McKesson confirms third-party cyber incident after ShinyHunters claims it compromised 284 million patient records and made a $55M ransom demand.
"CyberInsider reviewed samples privately provided by the threat actor that appear consistent with the types of information described in the data breach claims."
https://lnkd.in/e8NQwM-T
McKesson hasn't disclosed which third parties were involved, but if ShinyHunters is to be believed, they are the usual suspects. "ShinyHunters told BleepingComputer that the vishing attacks led to the compromise of multiple employees' Okta single sign-on accounts, which they then used to access the company's Salesforce and Snowflake environments."
https://lnkd.in/e8P8R97r
McKesson disclosed under Item 7.01 (Regulation FD)…not Item 1.05 (Material Cybersecurity Incidents) or 8.01. Interesting.
https://lnkd.in/efFnhxy5
McKesson Breach Page:
https://lnkd.in/ecaFxReu
[Update] 8/29/2026
"...[W]e’ve confirmed that the unauthorized access to certain third-party applications and the exfiltration of certain data was associated with a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units."
8/28/2026
SEC 8-K Item 7.01 Regulation FD Disclosure.
On August 25, 2026, McKesson Corporation discovered a cybersecurity incident affecting its information systems. An investigation of the incident is in its early stages. Information about the incident, including any updates, is available on the company's website at
https://lnkd.in/ezV3vhUK.
As of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations.
8/28/2026
McKesson is in the early stages of investigating a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data.
...Upon discovery, we immediately activated our incident response protocols, launched an investigation, and engaged leading cybersecurity industry experts to assist in our response.
Our investigation remains ongoing, and we are working to fully ascertain the nature and scope of the incident so that we can provide accurate and concrete information as it becomes available.
Our cybersecurity team and leading cybersecurity industry experts are working to minimize the impact on system availability and business operations. At this time, customers may experience intermittent service degradation that we believe may be related to this incident....
Based on the information currently available, we do not believe any action is required by our customers and we are not proactively disconnecting systems within our environment at this time. If you encounter technical issues with our services, please contact us through your normal support channels....