Bleepingcomputer
McKesson Investigates Major Data Breach Linked to ShinyHunters Group
Article Content
McKesson, a leading healthcare and pharmaceutical distributor, has reported a cybersecurity incident involving unauthorized access to third-party applications and the alleged theft of 284 million patient records by the ShinyHunters extortion group. The breach was discovered on August 25, 2026, and was publicly disclosed in a Form 8-K filing with the SEC. McKesson has activated its incident response protocols and is currently investigating the full scope of the incident. The attackers reportedly utilized voice phishing (vishing) to gain access to the company's systems, specifically targeting McKesson employees. Although the company has not disclosed which third-party applications were compromised, it has warned customers of potential service degradation. The investigation is ongoing, and McKesson has committed to providing updates as more information becomes available.
Key Points: • ShinyHunters claims to have stolen 284 million patient records from McKesson. • The breach was discovered on August 25, 2026, and disclosed the following day. • McKesson is investigating the incident and has activated its incident response protocols.
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.