started · updated
McKesson confirms major cyberattack and data theft
McKesson, a major U.S. pharmaceutical distributor, has confirmed a significant cybersecurity incident involving unauthorized access to certain third-party applications and cloud-hosted environments, including Snowflake and Salesforce. The company discovered the breach on August 25, 2026, following an intrusion that began around August 21.
The hacking group ShinyHunters has claimed responsibility for the attack, alleging they exfiltrated approximately 284 million records. The stolen data reportedly includes highly sensitive information such as names, addresses, Social Security numbers, medical diagnoses, medication histories, allergies, and clinical notes. The breach specifically impacted McKesson’s oncology, multispecialty, and medical-surgical business units.
ShinyHunters is reportedly demanding a ransom of 55 million dollars to prevent the public release of the stolen data. While McKesson has activated incident response protocols and engaged cybersecurity experts, the company noted that it expects intermittent service degradation. Despite the breach, McKesson stated that its business and distribution centers remain operational.
Entities
Francisco Fraga · McKesson · McKesson Corporation · Salesforce · ShinyHunters · Snowflake
Claims
What the coverage asserts, and how many sources carry each claim.
- [● 6 SOURCES] The data theft affected the company's oncology, multispecialty, and medical-surgical business units. espiganoticias.net · cybernoz.com · techcrunch.com · www.servicesmobiles.fr · www.economiematin.fr
- [● 2 SOURCES] The company's business and distribution centers remain operational. cybernoz.com
- [● 5 SOURCES] The hacking group ShinyHunters claimed responsibility for the cyberattack. espiganoticias.net · cybernoz.com · www.economiematin.fr · techcrunch.com
- [● 4 SOURCES] The attackers are demanding a ransom of 55 million dollars. espiganoticias.net · cybernoz.com · www.economiematin.fr · techcrunch.com
- [● 5 SOURCES] The company discovered the attack on August 25, 2026. cybernoz.com · www.it-boltwise.de · www.economiematin.fr
- [● 2 SOURCES] The attack was executed using phishing and social engineering techniques. espiganoticias.net · techcrunch.com
- [● 4 SOURCES] The group claims to have stolen approximately 284 million protected health information records. www.economiematin.fr · techcrunch.com · entrevue.fr
- [● 4 SOURCES] The breach involved unauthorized access to certain third-party applications. cybernoz.com · www.it-boltwise.de