McKesson Corp.: McKesson Data Breach: Investigation Ongoing

McKesson Corp.: McKesson Data Breach: Investigation Ongoing

McKesson Discloses Cybersecurity Breach Impacting Healthcare Customers in Late August 2026

McKesson Corp., a leading U.S. healthcare distributor supplying pharmaceuticals and medical products to pharmacies, hospitals, and clinics, reported a cybersecurity incident in late August 2026. The company first acknowledged the breach on August 28, 2026, stating it was investigating unauthorized access and data exfiltration involving third-party applications.

By August 29, 2026, McKesson provided further details, confirming that the breach affected a subset of customers in its Oncology & Infusion and Medical-Surgical divisions. The same day, the threat actor ShinyHunters claimed responsibility for the attack in a post on the Tor network, alleging they had breached McKesson’s database. The exact types of compromised data remain undetermined.

In response, McKesson has offered complimentary credit monitoring and identity protection services to potentially affected individuals, along with a dedicated support line for customers, partners, and patients. The company stated that further updates would be posted on McKesson.com/cybersecurity. The incident highlights ongoing risks to healthcare supply chains and third-party vulnerabilities.

Source: https://www.claimdepot.com/data-breach/mckesson-2026

McKesson Corp. TPRM report: https://www.rankiteo.com/company/mckesson-oncology-multispecialty

"id": "mck1788546683",
"linkid": "mckesson-oncology-multispecialty",
"type": "Breach",
"date": "9/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'customers_affected': 'Subset of customers in Oncology '
                                              '& Infusion and Medical-Surgical '
                                              'divisions',
                        'industry': 'Healthcare',
                        'location': 'U.S.',
                        'name': 'McKesson Corp.',
                        'type': 'Healthcare Distributor'}],
 'attack_vector': 'Third-party applications',
 'customer_advisories': 'Dedicated support line for customers, partners, and '
                        'patients; updates posted on '
                        'McKesson.com/cybersecurity',
 'data_breach': {'data_exfiltration': True},
 'date_detected': '2026-08-28',
 'date_publicly_disclosed': '2026-08-28',
 'description': 'McKesson Corp., a leading U.S. healthcare distributor, '
                'reported a cybersecurity incident involving unauthorized '
                'access and data exfiltration in third-party applications. The '
                'breach affected a subset of customers in its Oncology & '
                'Infusion and Medical-Surgical divisions. The threat actor '
                'ShinyHunters claimed responsibility for the attack.',
 'impact': {'brand_reputation_impact': True,
            'data_compromised': True,
            'identity_theft_risk': True,
            'systems_affected': 'Third-party applications'},
 'investigation_status': 'Ongoing',
 'references': [{'date_accessed': '2026-08-29',
                 'source': 'McKesson Corp. announcement',
                 'url': 'https://www.mckesson.com/cybersecurity'},
                {'date_accessed': '2026-08-29',
                 'source': 'ShinyHunters Tor network post'}],
 'response': {'communication_strategy': 'Updates posted on '
                                        'McKesson.com/cybersecurity; dedicated '
                                        'support line for customers, partners, '
                                        'and patients',
              'incident_response_plan_activated': True},
 'stakeholder_advisories': 'Complimentary credit monitoring and identity '
                           'protection services offered to potentially '
                           'affected individuals',
 'threat_actor': 'ShinyHunters',
 'title': 'McKesson Cybersecurity Breach Impacting Healthcare Customers',
 'type': 'Data Breach'}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.