McKesson Confirms Data Breach as ShinyHunters Claims Theft of 284 Million Patient Records
Healthcare and pharmaceutical distribution giant McKesson discloses a cybersecurity incident involving unauthorized access to third-party applications and data theft. The disclosure follows claims by the ShinyHunters extortion group that it has stolen 284 million patient data records from the company. McKesson reveals the incident in a Form 8-K filing with the U.S. Securities and Exchange Commission after CyberInsider first reports the breach.
McKesson says it discovers the incident on August 25, 2026, and its investigation remains in the early stages. In its SEC filing, the company states it has not yet determined the incident to be material or likely to have a material impact on its financial condition or results of operations. In a notice to customers, McKesson confirms the incident involves unauthorized access to and exfiltration of data from third-party applications, and says it immediately activates incident response protocols and engages leading cybersecurity experts to assist.
The company warns customers they may experience intermittent service degradation believed to be related to the attack, though it is not proactively disconnecting systems. McKesson has not disclosed which third-party applications are compromised, how the attackers gain access, or what information is stolen. ShinyHunters tells BleepingComputer it is behind the attack, and McKesson says it will provide additional information as its investigation develops a more complete understanding of the incident.