McKesson Confirms Data Breach as ShinyHunters Threatens to Leak Stolen Records
Healthcare and pharmaceutical giant McKesson Corporation disclosed a cybersecurity incident on August 25, revealing that hackers exfiltrated sensitive customer data from its systems. The company, which supplies roughly one-third of North America’s prescription medicines and operates the Health Mart pharmacy franchise, confirmed the breach affected third-party applications but stated its core services remained operational.
In a September 6 filing with the U.S. Securities and Exchange Commission (SEC), McKesson acknowledged the theft of data tied to "a subset of customers" within its Oncology & Multispecialty and Medical-Surgical business units. While the unauthorized access was disrupted, the company did not specify the type of data compromised, the number of affected individuals, or the attack’s origin. As a precaution, McKesson offered complimentary credit monitoring and identity protection to impacted parties.
The breach coincided with claims by the ShinyHunters extortion group, which added McKesson to its Tor-based leak site on the same day. Known for high-profile data breaches, ShinyHunters threatened to publicly release the stolen data by September 1 unless McKesson engaged in ransom negotiations. The group alleged the theft of 284 million customer records, including personally identifiable information (PII), protected health information (PHI), medical and treatment records, prescription and billing data, employee records, and details on customer physicians and clinics. They also demanded a $55 million ransom.
McKesson has not confirmed the hackers’ claims, and its response to the extortion attempt remains unclear. The incident underscores the growing threat of data extortion attacks targeting critical healthcare infrastructure.
Source: https://www.securityweek.com/mckesson-confirms-data-breach-as-attacker-deadline-looms/
McKesson Corporation cybersecurity rating report: https://www.rankiteo.com/company/mckesson-corporation
"id": "MCK1788186326",
"linkid": "mckesson-corporation",
"type": "Breach",
"date": "8/2026",
"severity": "100",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'A subset of customers in '
'Oncology & Multispecialty and '
'Medical-Surgical business units',
'industry': 'Healthcare and Pharmaceutical',
'location': 'North America',
'name': 'McKesson Corporation',
'size': 'Large (supplies one-third of North America’s '
'prescription medicines)',
'type': 'Corporation'}],
'attack_vector': 'Third-party applications',
'customer_advisories': 'Credit monitoring and identity protection offered to '
'impacted parties',
'data_breach': {'data_exfiltration': 'Yes',
'number_of_records_exposed': '284 million (alleged by '
'ShinyHunters)',
'personally_identifiable_information': 'Yes',
'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Personally Identifiable '
'Information (PII)',
'Protected Health Information '
'(PHI)',
'Medical and treatment records',
'Prescription and billing data',
'Employee records',
'Details on customer physicians '
'and clinics']},
'date_detected': '2023-08-25',
'date_publicly_disclosed': '2023-09-06',
'description': 'Healthcare and pharmaceutical giant McKesson Corporation '
'disclosed a cybersecurity incident where hackers exfiltrated '
'sensitive customer data from its systems. The breach affected '
'third-party applications but core services remained '
'operational. The ShinyHunters extortion group claimed '
'responsibility and threatened to leak stolen records unless a '
'ransom was paid.',
'impact': {'data_compromised': 'Sensitive customer data, PII, PHI, medical '
'and treatment records, prescription and '
'billing data, employee records, details on '
'customer physicians and clinics',
'identity_theft_risk': 'High',
'operational_impact': 'Core services remained operational',
'systems_affected': 'Third-party applications'},
'investigation_status': 'Ongoing',
'motivation': 'Extortion',
'ransomware': {'data_exfiltration': 'Yes', 'ransom_demanded': '$55 million'},
'references': [{'date_accessed': '2023-09-06', 'source': 'SEC Filing'},
{'date_accessed': '2023-09-06',
'source': 'ShinyHunters Tor-based leak site'}],
'regulatory_compliance': {'regulatory_notifications': 'SEC filing'},
'response': {'communication_strategy': 'SEC filing, credit monitoring and '
'identity protection offered to '
'impacted parties',
'containment_measures': 'Unauthorized access was disrupted'},
'threat_actor': 'ShinyHunters',
'title': 'McKesson Data Breach by ShinyHunters',
'type': 'Data Breach'}