McKesson Discloses Breach After ShinyHunters Claims Theft of 284 Million Patient Records
McKesson, one of the world's largest pharmaceutical and healthcare distribution companies, disclosed in an SEC Form 8-K that a cybersecurity incident discovered on 25 August 2026 involved unauthorised access to third-party applications and data exfiltration. The investigation is in its early stages, materiality has not yet been determined, and the company warned customers of possible intermittent service degradation without proactively disconnecting systems. McKesson has not disclosed which third-party applications were compromised or what data was taken.
The extortion group ShinyHunters told BleepingComputer it was behind the attack, claiming 284 million patient records and saying it gained access through vishing (voice phishing) campaigns against multiple McKesson employees. The scale figure remains the group's claim and has not been independently verified. The incident extends ShinyHunters' 2026 healthcare sweep โ Medtronic, DentaQuest, iRhythm, OneMedical and AdaptHealth โ and lands in a week in which Baxter, CareCloud and the Hospital for Sick Children also disclosed breaches. For Australian pharmaceutical supply chains it is a distributor-scale compromise reminder, with vishing demonstrated as the initial-access vector against healthcare workers.