< Back to all clusters
[TECHNOLOGY] · United States · 17 sources

started · updated

McKesson confirms major cyberattack and data theft

McKesson, a major U.S. pharmaceutical distributor, has confirmed a significant cybersecurity incident involving unauthorized access to certain third-party applications and cloud-hosted environments, including Snowflake and Salesforce. The company discovered the breach on August 25, 2026, following an intrusion that began around August 21.

The hacking group ShinyHunters has claimed responsibility for the attack, alleging they exfiltrated approximately 284 million records. The stolen data reportedly includes highly sensitive information such as names, addresses, Social Security numbers, medical diagnoses, medication histories, allergies, and clinical notes. The breach specifically impacted McKesson’s oncology, multispecialty, and medical-surgical business units.

ShinyHunters is reportedly demanding a ransom of 55 million dollars to prevent the public release of the stolen data. While McKesson has activated incident response protocols and engaged cybersecurity experts, the company noted that it expects intermittent service degradation. Despite the breach, McKesson stated that its business and distribution centers remain operational.

Entities

Francisco Fraga · McKesson · McKesson Corporation · Salesforce · ShinyHunters · Snowflake

Claims

What the coverage asserts, and how many sources carry each claim.

Sources