Back to Feed
BreachesAug 31, 2026

McKesson Confirms Data Breach as Attacker Deadline Looms

McKesson confirms data breach after ShinyHunters claims theft of 284 million records.

Summary

Healthcare giant McKesson has confirmed a cybersecurity incident where hackers exfiltrated customer data from its systems. The ShinyHunters extortion group claims to have stolen 284 million records, including PII, PHI, and medical information, and is demanding a $55 million ransom. McKesson stated the unauthorized access has been disrupted and services are unaffected, while offering credit monitoring to impacted individuals.

Full text

Healthcare giant McKesson Corporation over the weekend confirmed that hackers exfiltrated customer data from its systems, as the ShinyHunters extortion group is threatening to release the stolen information. McKesson delivers roughly one-third of prescription medicines to North American hospitals, pharmacies, and healthcare clinics. It also provides medical supplies, supports cancer treatment and specialty care, and operates the Health Mart pharmacy franchise. In a filing with the US Securities and Exchange Commission, the healthcare and pharma giant said it discovered “a cybersecurity incident affecting its information systems” on August 25. In a Friday notice on its website, the company said the incident involved third-party applications and data theft, but noted that it was not disconnecting any systems in response. On Saturday, McKesson confirmed that the hackers had exfiltrated data associated with “a subset of customers within our Oncology & Multispecialty and Medical-Surgical business units”. The company said that the unauthorized access to its systems had been disrupted, and underlined that its services were not affected by the incident, and that complimentary credit monitoring and identity protection services would be provided to the impacted individuals.Advertisement. Scroll to continue reading. However, the healthcare giant did not share details on the type of data that was exfiltrated, the number of affected people, or who was behind the attack. McKesson’s disclosure came around the same time that the notorious extortion group ShinyHunters added the company to its Tor-based leak site. Responsible for multiple high-profile data breaches over the past couple of years, ShinyHunters is known to demand ransom payments in exchange for deleting data exfiltrated from its victims. In McKesson’s case, the hacking group is threatening to make the stolen information public unless the company contacts them to start payment negotiations by September 1. ShinyHunters reportedly boasted about stealing 284 million customer records from McKesson and about demanding approximately $55 million from the company. The compromised information allegedly includes personally identifiable information (PII), protected health information (PHI), medical and treatment information, prescription and billing records, employee records, and information about McKesson’s customer physicians and clinics. SecurityWeek has contacted McKesson for a statement on the hackers’ claims and will update this article if the company responds. Related: Boston Scientific Still Recovering From Cyberattack Related: Extortion Group Claims Manchester Airports Group Data Breach Related: Berlin Won’t Pay Extortion Group Claiming Data Theft Related: Hasbro Data Breach Exposed Employee Personal Information Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Critical Isolated-vm Vulnerability Leads to RCE on HostRust Supply Chain Attack Linked to North Korean HackersMicrosoft Patches Exploited Entra ID VulnerabilityCISA Urges Immediate Patching of Exploited TrueConf VulnerabilitiesThreat Actor Hacks 14,000 IP Cameras in Ukraine and RussiaAtlassian, Splunk Patch Dozens of Critical, High-Severity VulnerabilitiesMLflow Vulnerability Exploited for Cloud Credential TheftCisco Patches Critical Crosswork, Secure Workload Vulnerabilities Latest News ServiceNow Patches 3 Critical Code Injection VulnerabilitiesWhat the Hugging Face Incident Teaches Security Leaders About AI Agent AccessAnthropic Warns Claude Users of Infostealer Malware InfectionsCritical Ruby on Rails Vulnerability in Attackers’ CrosshairsBoston Scientific Still Recovering From CyberattackExtortion Group Claims Manchester Airports Group Data BreachJudge Says Pentagon’s Measures Against Anthropic Were ‘Illegal and Baseless’Berlin Won’t Pay Extortion Group Claiming Data Theft Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Attack Surface Management Summit 2026 September 16, 2026 Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs. Register Webinar: Minimum Viable Business: Can You Prove Your Organization Would Recover? September 2, 2026 In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk. Register People on the MoveSocial engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer.Naveen Bhateja has been appointed Chief People Officer at HackerOne.The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer.More People On The MoveExpert Insights What the Hugging Face Incident Teaches Security Leaders About AI Agent Access Security teams must treat autonomous agents as highly privileged identities. (Etay Maor) The Future of AI-Driven Security Depends on Complete Data For twenty-five years, "data" in security meant logs and events. But logs are a lossy representation of reality. (Danelle Au) The MFA Identity Trap: When Authentication Creates a False Sense of Security Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop. (Torsten George) Silent Patches Don’t Stop Attackers – They Blind Defenders Silent patches can become exploit intelligence for attackers while leaving defenders without the context needed to prioritize risk. (Tod Beardsley) Hired for One Job, Judged on Another: The CISO’s Real Problem The skills that get a CISO hired are rarely the skills they are judged on later. Most security leaders are stuck in that gap. Closing it is the real job. (Sravish Sridhar) Flipboard Reddit Whatsapp Whatsapp Email

Entities

McKesson (vendor)ShinyHunters (threat_actor)