McKesson Investigates Major Data Breach Linked to ShinyHunters Group

McKesson Investigates Major Data Breach Linked to ShinyHunters Group

First seen 29 Aug 2026, 01:56 UTC Bleepingcomputerwww.mckesson.comDatabreaches 64.5

Article Content

Browse articles
ThreatCluster

McKesson, a leading healthcare and pharmaceutical distributor, has reported a cybersecurity incident involving unauthorized access to third-party applications and the alleged theft of 284 million patient records by the ShinyHunters extortion group. The breach was discovered on August 25, 2026, and was publicly disclosed in a Form 8-K filing with the SEC. McKesson has activated its incident response protocols and is currently investigating the full scope of the incident. The attackers reportedly utilized voice phishing (vishing) to gain access to the company's systems, specifically targeting McKesson employees. Although the company has not disclosed which third-party applications were compromised, it has warned customers of potential service degradation. The investigation is ongoing, and McKesson has committed to providing updates as more information becomes available.

Key Points: • ShinyHunters claims to have stolen 284 million patient records from McKesson. • The breach was discovered on August 25, 2026, and disclosed the following day. • McKesson is investigating the incident and has activated its incident response protocols.

Timeline

2026-08-25
McKesson discovers cybersecurity incident
Unauthorized access to third-party applications was identified, prompting an internal investigation.
BleepingComputer
2026-08-28
McKesson publicly discloses breach
The company filed a Form 8-K with the SEC confirming the data theft and ongoing investigation.
BleepingComputer
2026-08-28
ShinyHunters claims responsibility
The extortion group stated they gained access through vishing attacks targeting McKesson employees.
BleepingComputer