![]()
McKesson, one of the largest wholesale medical supply, pharmaceutical distribution and healthcare technology companies in the United States, is still investigating a cyberattack that exposed sensitive personal and medical data. The breach affects patients, staff and marketing contacts tied to the company, and the full number of people impacted has not yet been determined.
As your consumer reporter, I track breaches like this one closely because the fallout often lands on ordinary people long after the headlines fade. If you have ever done business with McKesson or its healthcare partners, this is worth your attention.
McKesson first disclosed the incident in a Form 8-K filing with the Securities and Exchange Commission, saying it involved unauthorized access to third-party applications and the exfiltration of data. According to the filing, the intrusion was first detected on August 25, 2026. On September 8, 2026, McKesson issued an update confirming that the data likely taken includes names, addresses, phone numbers, email addresses, patient IDs and dates of birth, along with one or more of the following: health insurance information including Medicaid and Medicare ID numbers, medical information such as diagnoses and treatment records, billing and payment details including credit or debit card numbers, and other identifying information such as Social Security numbers.
The ShinyHunters extortion group has claimed responsibility, saying it stole 284 million rows of raw patient data, though that figure does not represent 284 million unique patients. Troy Hunt of HaveIBeenPwned has reported that the stolen dataset includes 6.4 million unique email addresses tied to marketing campaigns, patients and staff. According to BleepingComputer, which was in contact with the group, about 1 terabyte of data was taken between August 21 and August 25, 2026, and a ransom demand of more than $55 million was issued.
McKesson has said the incident appears tied to a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units, and that no further unauthorized activity has been detected. The company says it continues to serve customers, accept orders and ship products.
How to spot it
- Unexpected emails or calls referencing McKesson, your pharmacy or healthcare provider
- Requests for personal, medical or financial details you did not initiate
- Unfamiliar charges or insurance claims appearing under your name
What to do if it happened to you
McKesson has said customers do not need to take any action at this time and that it is not proactively disconnecting systems. The company has engaged third-party cybersecurity experts and added new security measures to monitor for related activity. It has not disclosed further steps for affected individuals.
Source: The HIPAA Journal