McKesson, one of North America's largest pharmaceutical distributors with $403.4 billion in annual revenue, disclosed a cyberattack on August 28, 2026, three days after discovering it. Unauthorized access to certain third-party applications led to data theft affecting a subset of customers within its Oncology & Multispecialty and Medical-Surgical business units, the company says.
ShinyHunters claimed responsibility, though McKesson has not named the group. It says it used voice phishing to compromise employees' Okta single sign-on accounts, then reached the Salesforce and Snowflake environments and exfiltrated data between August 21 and August 25, claiming roughly 284 million records and demanding over $55 million.
That figure counts database rows rather than patients, and the group has not fully analyzed the data. None of its claims are independently verified. A September 1 deadline to open negotiations passed without a response from the company, which has declined to comment on the demand.
Its distribution centers remain operational, McKesson says, though it warned customers to expect intermittent service degradation. Health-ISAC had warned the healthcare sector about ShinyHunters just weeks before the breach.
Source: CyberScoop