HackMyIP
← Back to News
2026-08-31 The Record

McKesson Confirms Data Breach: ShinyHunters Hit Healthcare Giant

Data BreachThreat IntelIncident Response

Pharmaceutical and healthcare technology distributor McKesson disclosed a cybersecurity incident on Friday, filing an 8-K with the Securities and Exchange Commission (SEC) and warning customers of "intermittent service degradation." CTO Francisco Fraga confirmed that attackers gained access to an unnamed third-party application and were actively exfiltrating data at the time of disclosure. By Saturday, the company confirmed that the stolen data was tied to customers in its oncology and surgical business units, prompting an offer of credit monitoring and identity protection services to affected individuals. McKesson stated it has received "reasonable assurance" that threat actors no longer maintain access to its systems and has not proactively disconnected services, suggesting this is not a ransomware-driven encryption event but a data theft operation.

The ShinyHunters cybercrime group claimed responsibility for the attack late Friday, posting a threat of potential data leaks on their extortion blog. The financially motivated threat actor has been active for over two years, targeting major enterprises including AT&T, Ticketmaster, Carnival Cruises, and gaming firm Rockstar. Earlier in 2025, the FBI issued an advisory warning that ShinyHunters affiliates were leveraging compromised Salesforce environments to steal corporate data and demand substantial ransom payments — a tactic consistent with the third-party application vector McKesson described. In May, the group breached a widely used educational software platform affecting millions, and in April it struck the world's largest medical device manufacturer, compromising data on more than four million individuals. McKesson joins Boston Scientific and Medtronic among major healthcare companies targeted this year, though McKesson handled its disclosure differently by opting for transparency over operational shutdown.

McKesson reported $106 billion in revenue last quarter and distributes roughly one-third of all prescriptions in North America, making this breach particularly significant for healthcare supply chain security. The Texas-based company distributes pharmaceuticals, produces oncology drugs, and manufactures critical medical-surgical supplies and laboratory equipment. Organizations in healthcare and adjacent sectors should treat this incident as a reminder to audit third-party application integrations and enforce strict access controls on externally connected platforms. For individuals concerned about exposure, check whether your data appears in known incidents using an email breach checker, verify that your account credentials remain strong with a password checker, and audit any third-party app permissions linked to corporate systems. McKesson has not identified the compromised application or provided a timeline for full remediation as of publication.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →