McKesson says data was taken from certain third-party applications tied to some customers. The company has not said what data was involved or how many people may be affected.
What to know
- McKesson says it discovered the incident on August 25, 2026.
- The company says unauthorized access involved certain third-party applications and a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units.
- ShinyHunters claims it stole about 284 million records, but McKesson has not confirmed that number or the type of data involved.
- McKesson has not confirmed that any particular category of patient information was accessed.
- People should check McKesson’s official advice and verify unexpected healthcare-related messages through a trusted channel.
Why this matters to patients and families
McKesson says attackers gained unauthorized access to certain third-party applications and took data. A third-party application is software or an online service provided by another company. McKesson says the activity was tied to a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units.
McKesson says it discovered the incident on August 25, 2026, and that its investigation is still in its early stages. It has not said how much data was taken, what the data contains, or whether any particular patient was affected.
The report does not establish that every McKesson customer, patient, or pharmacy customer was involved. People should rely on McKesson’s official notices for information about whether they are affected.
What McKesson confirmed—and what remains a claim
McKesson said unauthorized access to certain third-party applications and the removal of data were associated with a subset of customers. Data removal from a system is often called exfiltration, meaning information was copied or taken out without permission.
The ShinyHunters extortion group claims responsibility. According to the Malwarebytes report, the group told BleepingComputer that it used voice phishing, also called vishing. Vishing is a social-engineering scam carried out by phone or voice message.
The group claims it targeted McKesson employees, used compromised Okta single-sign-on accounts, and reached Salesforce and Snowflake environments. It also claims to have removed about 1 terabyte of data between August 21 and 25. These details come from the group’s claim, not from McKesson’s confirmed findings.
ShinyHunters also claims the data contains about 284 million records. That number does not necessarily represent 284 million unique patients. McKesson has not confirmed the amount, nature, or categories of the stolen data.
How a possible follow-up scam could sound
Malwarebytes says a mix of identity details and healthcare-related information could help criminals impersonate a pharmacy, insurer, medical provider, debt collector, or patient-support service. A message might mention a supposed prescription problem, unpaid claim, delivery issue, appointment change, or request to verify insurance details.
These are possible scam patterns, not confirmed examples of criminals using McKesson data. McKesson has not confirmed that a particular category of patient information was accessed.
If an unexpected healthcare message creates pressure to act, pause. Contact the organization through a phone number or website you already know. Do not use the link, number, or reply address in the unexpected message.
What to do while the investigation continues
Check McKesson’s official advice for information about the incident and any instructions for affected people. The right response can differ depending on what data was involved.
If McKesson’s guidance indicates that a related account or password was involved, change that password anywhere it was reused. Use a different strong password for each account. A password manager can create and store those passwords.
Turn on two-factor authentication, or 2FA, where available. 2FA adds a second proof of identity after the password. Malwarebytes says a FIDO2 security key, laptop, or phone can provide a form of 2FA that cannot be phished in the same way as a code or password.
You can also consider identity monitoring if you want alerts about personal information being traded online. Monitoring does not confirm that you were affected, so do not wait for an alert before checking official notices.
Does this affect me?
- Who may be affected
- McKesson customers connected to the Oncology & Multispecialty and Medical-Surgical business units should pay attention to official notices. The report does not establish that people outside the identified customer subset were affected; everyone should rely on McKesson’s official notices for applicability.
- How to check
- Check McKesson’s official website or a direct notice from the company for information about whether your account, organization, or data is involved.
- What to do
- If official guidance says a related password may be involved, change it anywhere it was reused and turn on two-factor authentication where available.
- What to avoid
- Do not click links, call numbers, share insurance details, or act under pressure because an unexpected message mentions a prescription, claim, delivery, appointment, or security problem.
Common questions
Does the report confirm that 284 million patients’ records were stolen?
No. ShinyHunters claims that about 284 million records were taken, but that number may not represent unique patients. McKesson has not confirmed the amount, nature, or categories of data involved.
Who may be connected to the confirmed incident?
McKesson says the incident was associated with a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. The supplied report does not identify every affected customer or person.
What should I do if I receive a message about a McKesson-related prescription or claim?
Do not use the message’s links or phone numbers. Check McKesson’s official website or contact the organization through a separate, trusted channel. Verify the request before sharing information.
Were Okta, Salesforce, or Snowflake customers broadly breached?
The report says ShinyHunters claimed it used compromised Okta single-sign-on accounts to access Salesforce and Snowflake environments. It does not establish a broad breach of those services or show that every customer of any of them was affected.
Primary source
This article is based on Malwarebytes’ report, “McKesson confirms cyber incident after ShinyHunters claims patient-data theft.” The report cites McKesson’s statement and separates the company’s confirmed findings from ShinyHunters’ claims. Read the complete original source.
Get the important updates without the noise
Choose the devices and topics you care about in Cyber Alerts.
Article history: Published Aug 31, 2026 at 10:49 am EDT. Updates and corrections are noted here when material facts change.
