The healthcare giant is investigating unauthorized access to third-party applications as questions grow over the information that may have been taken
Irving, Texas, 1 September 2026 – McKesson is investigating a cybersecurity incident involving unauthorized access to certain third-party applications and the removal of some data from its systems. The incident has placed renewed attention on the growing cybersecurity risks facing healthcare organizations that manage large volumes of sensitive information.
McKesson discovered the incident on August 25 and disclosed it in a filing with the US Securities and Exchange Commission. The company said its investigation is still in its early stages and that the activity involved its Oncology and Multispecialty and Medical Surgical business units.
In a subsequent update, McKesson said it has reasonable assurance that there is no continuing unauthorized activity within its systems. The company also stated that customers can continue to use its systems and services as normal.
McKesson has continued accepting orders, while its distribution centers remain operational and products continue to move through its distribution network. This means the incident has not resulted in a broad interruption to the company’s core distribution activities, according to its latest customer communication.
However, the incident has attracted significant attention because the cyber extortion group ShinyHunters has claimed responsibility. The group alleges that it obtained information connected to 284 million patient records and has demanded approximately $55 million from McKesson. These figures are claims made by the attackers and have not been confirmed by McKesson.
The exact amount and type of information involved are still being determined. Reports about the attackers’ claims have mentioned personal information such as names, addresses, dates of birth, telephone numbers and email addresses. The claims also include healthcare identifiers and potentially sensitive clinical information. McKesson has not confirmed that all of these categories of information were affected.
The reported attack also highlights the growing importance of employee awareness in healthcare cybersecurity. ShinyHunters has claimed that it used voice phishing, also known as vishing, to gain access through employees. Vishing involves using phone-based social engineering to persuade people to provide information or access that can later be used by attackers.
Healthcare organizations are particularly attractive targets because their systems can contain valuable personal, financial, and medical information. Hospitals, pharmaceutical companies, medical suppliers and healthcare technology providers increasingly depend on connected digital platforms to manage everything from patient information to orders and distribution.
Third-party applications can create another layer of cybersecurity challenges. Modern businesses often rely on external software and cloud platforms for customer management, data storage, communications, and other operations. These connections can improve efficiency, but they also need strong security controls because unauthorized access through one application can potentially expose information connected to other systems.
The McKesson incident demonstrates why organizations need to look beyond their own internal networks when protecting sensitive data. Strong passwords and basic security measures remain important, but companies also need effective identity management, employee training, access controls, monitoring, and regular assessments of third-party technology providers.
The incident is part of a wider period of increased cybersecurity pressure across the healthcare sector. Other major healthcare and medical technology organizations have also reported cybersecurity incidents in recent months, highlighting the continuing challenge of protecting digital healthcare infrastructure.
For McKesson, the immediate priority is determining exactly what happened and what information may have been accessed or removed. The company has said it activated its incident response procedures after discovering the issue and brought in cybersecurity specialists to support its investigation.
McKesson has also indicated that it will provide support to individuals whose information is confirmed to have been exfiltrated. This includes credit monitoring and identity protection services, along with information resources for affected partners, customers and patients.
The company’s investigation will be closely watched because the consequences of a healthcare data incident can extend beyond technology systems. Personal information can remain valuable to cybercriminals long after an attack has ended, making timely investigation, notification and protection measures important.
At this stage, separating confirmed information from claims made by the attackers remains essential. McKesson has confirmed unauthorized access to certain third-party applications and the exfiltration of certain data, but the full scope of the incident is still being investigated.
The episode serves as another reminder that healthcare cybersecurity is becoming a fundamental part of modern healthcare operations. As more healthcare services move into connected digital environments, organizations will need to protect not only their own systems but also the wider network of applications, employees and technology partners that support their operations.
For McKesson, the next step is clarity. As its investigation progresses, further information should help determine what data was affected, how the unauthorized access occurred, and what additional measures may be required to strengthen security.

