McKesson disclosed on Sept. 2, 2026 that an unauthorized individual gained access to some of its third-party applications and stole data. The company identified the impact as limited to a subset of customers within its oncology, multispecialty, and medical-surgical business lines. McKesson reported it has reasonable assurance there is no continuing unauthorized activity and that its businesses and distribution network remain operational.
McKesson has not publicly determined whether the incident is material, according to a securities filing cited by the company. The organization did not report the number of affected individuals or full details of the data taken in its public statements.
The breach was described as affecting customers in McKesson’s oncology and medical-surgical businesses, as well as its multispecialty operations. The company characterized the incident as involving access to third-party cloud applications rather than direct compromise of its primary distribution systems.
McKesson positions itself as a highly connected logistics and supply intermediary in U.S. healthcare, reporting roughly 40,000 deliveries each day to a broad range of care sites. That connected role has informed observers’ concerns about the potential reach of breaches, even when a company reports limited operational disruption.
The hacking group ShinyHunters publicly claimed responsibility for the breach and told cybersecurity outlet BleepingComputer that it used voice phishing (vishing) to compromise employee accounts and then accessed cloud applications. McKesson has not confirmed the group’s statement, and BleepingComputer reported it could not independently verify the claim.
McKesson’s public materials stated an unauthorized person accessed third-party applications, but the company did not confirm details about the intrusion technique beyond that statement. The precise number of accounts or records accessed was not disclosed in the company release or the referenced securities filing.
According to McKesson, its distribution network and core businesses remain operational and the company has reasonable assurance that there is no ongoing unauthorized activity. The firm has not yet concluded whether the incident is material under disclosure rules, per its SEC filing.
At the time of disclosure, McKesson had not provided an estimate of affected individuals or full details on the types of data taken. The company’s statements emphasized continuity of business operations and the distinction between the breach of third-party applications versus a collapse of core distribution services.
Industry observers noted that the method described by ShinyHunters—if accurate—fits a broader pattern whereby threat actors use social engineering, including voice phishing, to hijack single-sign-on credentials or employee accounts and then move into connected cloud applications. The nonprofit Health Information Sharing and Analysis Center (Health-ISAC) had previously warned that ShinyHunters was increasingly using such techniques to take over accounts and compromise cloud environments.
Scott Gee, deputy national adviser for cybersecurity and risk at the American Hospital Association, highlighted a common challenge: activity from a compromised employee account often looks legitimate, making these intrusions harder to detect. Once an account is compromised, attackers can access resources and data that the employee is authorized to reach.
Recent healthcare breaches reflect similar routes of compromise. For example, AdaptHealth disclosed that a cybercriminal used social engineering to access cloud-based applications and stole health information. Those incidents differ in scale and impact from the 2024 Change Healthcare ransomware attack, which caused widespread operational disruption; experts have contrasted the McKesson incident with Change Healthcare to illustrate different forms of systemic risk posed by deeply embedded intermediaries in healthcare.
The full scope of McKesson’s breach remains unclear based on the public disclosures: the company affirmed operational continuity and noted ongoing investigation, ShinyHunters claimed responsibility but the claim was not independently verified, and the number of affected individuals was not reported. Stakeholders and customers may await further details from McKesson as its review and any required regulatory disclosures proceed.