McKesson Corporation, the country’s largest pharmaceutical distributor, has confirmed a cybersecurity incident just days after an extortion group claimed it stole roughly a terabyte of data, including patient identifiers and medical details, and demanded $55.2 million in ransom.
McKesson Corporation disclosed in a Securities and Exchange Commission Form 8-K and a separate customer notice, both filed August 28, 2026, that it discovered a cybersecurity incident on August 25, 2026. In its own words, the incident involved “unauthorized access to third-party applications and … exfiltration of data.” McKesson has not confirmed which third-party applications were affected, how the attackers gained access, what specific data was taken, or how many people are affected. The company’s SEC filing states that it has not yet determined whether the incident is material.
Source: SEC EDGAR, McKesson Corporation Form 8-K, Item 7.01 (filed 08/28/2026); BleepingComputer, SecurityWeek, and HIPAA Journal reporting on the incident (08/28/2026).
What the Extortion Group Claims
The ShinyHunters extortion group told BleepingComputer it was behind the attack. According to the group, it used voice phishing, known as vishing, against multiple McKesson employees to compromise their Okta single sign-on credentials, then used that access to reach McKesson’s Salesforce and Snowflake environments, where it exfiltrated data between August 21 and August 25, 2026. ShinyHunters claims it took approximately 284 million records from Snowflake, but the group itself has clarified that this is a raw record count, not a count of unique individuals, and that it has not analyzed the data closely enough to say how many people are actually affected. ShinyHunters says it demanded $55,236,150 in ransom on August 25, 2026, and that McKesson did not respond or negotiate.
None of the extortion group’s claims have been confirmed by McKesson.
What Information May Be at Risk?
According to the extortion group’s own, unconfirmed claims, the data taken may include:
- Names, addresses, and dates of birth
- Social Security numbers
- Patient identification numbers
- Phone numbers and email addresses
- Medicaid numbers and medical record numbers
- Medication, allergy, illness, and disability information
- Appointment and physician information
- Prescription and shipment records
- Employee data and internal Salesforce records and communications
McKesson has not confirmed any of these specific categories were involved. This list reflects the extortion group’s own claims, reported by cybersecurity press, not McKesson’s official statement.
How Many People Are Affected?
McKesson has not disclosed a total number of affected individuals. As noted above, the extortion group’s 284-million figure is a raw record count, by the group’s own admission, not a confirmed number of unique people.
Your Information May Be at Risk
If the extortion group’s claims are accurate, the combination of Social Security numbers, Medicaid numbers, and detailed medical information would create serious risk of both identity theft and medical identity theft, including someone using your insurance or Medicaid information to obtain treatment or file fraudulent claims in your name. Affected individuals should watch for a notice letter from McKesson and monitor financial accounts, insurance statements, and credit reports for unfamiliar activity.
Do You Have Legal Options?
Companies that collect and store Social Security numbers, medical information, and other sensitive personal data have a legal duty to secure that data and to notify affected individuals without unreasonable delay.
Contact the Data Breach Attorneys at Emery | Reddy today for a Free Case Review if you receive a notice letter from McKesson Corporation.
Your Personally Identifiable Information (PII) includes information that can be used to identify you, such as your name and other personal details. Organizations that manage healthcare data are legally required to safeguard this information. When PII is exposed in a data breach, it can potentially be used by cybercriminals to commit identity theft, financial fraud, or other misuse.
Much of the information involved in this incident may also qualify as Protected Health Information (PHI). PHI includes medical or healthcare-related data protected under federal and state privacy laws. When PHI is compromised, it can be misused for medical identity theft or insurance fraud.
FAQ
Who is affected by the McKesson data breach?
McKesson has not yet disclosed a total number of affected individuals or confirmed which specific data categories were involved. As McKesson’s investigation continues, more details are expected.
What happened?
McKesson discovered a cybersecurity incident on August 25, 2026, involving unauthorized access to third-party applications and confirmed data exfiltration, according to its own SEC filing. An extortion group called ShinyHunters has claimed responsibility and says it used a phishing scheme against employees to gain access.
Did McKesson pay the ransom?
According to the extortion group, McKesson did not pay or negotiate after a $55.2 million ransom demand issued August 25, 2026. McKesson has not independently confirmed this.
Is the 284 million figure accurate?
The extortion group itself has clarified that 284 million is a raw record count from the data it says it took, not a count of unique individuals, and that it has not determined how many people are actually affected. Treat this figure with caution until McKesson or a regulator confirms a specific number.
Has a lawsuit been filed against McKesson over this?
Not that we’ve found as of this writing. Emery | Reddy is currently investigating potential claims and gathering information from affected individuals.
Do I have a legal claim?
Companies that collect and store sensitive personal and medical information have a legal duty to secure that data and to notify affected individuals without unreasonable delay. If you receive a notice letter from McKesson Corporation, contact the Data Breach Attorneys at Emery | Reddy at 206.207.8929 or www.emeryreddy.com for a Free Case Review. No Fee Unless We Recover.