
McKesson Corp., a major U.S.-based healthcare company that distributes pharmaceuticals and medical products to pharmacies, hospitals and clinics, disclosed a cybersecurity incident in late August 2026.
McKesson posted a notice on its website on Aug. 28, 2026, announcing the incident. The company announced it was in the early stages of investigating a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data.
The following day, on Aug. 29, 2026, McKesson provided an update with additional details about the scope of the incident. The company confirmed that the unauthorized access to certain third-party applications involved the activation of certain data associated with a subset of Oncology & Infusion and Medical-Surgical customers.
Furthermore, on Aug. 29, 2026, a threat actor known as ShinyHunters claimed responsibility for the breach on the dark web. The claim was posted on the Tor network and alleged that ShinyHunters had breached McKesson's database.
The specific types of personal information that may have been accessed or taken have not yet been fully determined.
For individuals who may have been affected, McKesson has committed to providing complimentary credit monitoring and identity protection services, as well as a dedicated information line to answer questions and provide support to partners, customers and their patients.
The company said that any future updates about the nature and scope of the incident would come from McKesson and be posted on McKesson.com/cybersecurity.








.webp)
.webp)
.webp)

.webp)
.webp)
.webp)
.webp)