McKesson disclosed that it discovered a cybersecurity incident affecting its information systems on August 25, 2026.
What happened
According to the company’s cybersecurity notice, the incident involved unauthorized access to third-party applications and the exfiltration, or removal, of data. McKesson activated its incident response procedures, began investigating the scope of the attack, and engaged cybersecurity specialists. It also warned customers that they could experience intermittent service degradation, although the company said it was not proactively disconnecting systems.
In an August 28 SEC filing, McKesson said the investigation remained in its early stages and that it had not determined the incident was material or likely to affect its finances or operations materially. The ShinyHunters extortion group claimed responsibility and alleged that it used voice phishing to compromise employees’ Okta single sign-on accounts before accessing Salesforce and Snowflake. The group claimed it removed approximately one terabyte of data, including 284 million patient-related records. The figure represents database rows rather than 284 million individual patients. CyberInsider said samples supplied by the group appeared consistent with its description.
What was said
According to the SEC filing, “On August 25, 2026, McKesson Corporation discovered a cybersecurity incident affecting its information systems. An investigation of the incident is in its early stages. Information about the incident, including any updates, is available on the company’s website at www.mckesson.com/cybersecurity.”
Why it matters
The McKesson incident closely resembles the ShinyHunters attack against Abbott Laboratories, which Paubox covered in July 2026. Abbott confirmed unauthorized access involving its Cancer Diagnostics business and a third-party-hosted LabCentral portal, while ShinyHunters claimed it had exfiltrated millions of customer records, medical orders and doctor-patient communications. Abbott did not verify the group’s account or find evidence that patient care or sensitive customer information had been affected. McKesson’s disclosure follows a similar pattern. The company has confirmed unauthorized access to third-party applications and data exfiltration, but the claimed theft of 284 million patient-related database records remains unverified.
Both incidents demonstrate why attacker statements must be separated from findings established through forensic investigations and regulatory notifications. A study of 209 healthcare delivery organizations further explains the significance of third-party access. It found that 56.4% had experienced a breach involving a third party during the previous year, while only 51.1% maintained a comprehensive inventory of third parties with network access. The study also found that 60% did not routinely monitor third-party access to sensitive information, showing how interconnected vendor systems can expand the paths attackers use to reach healthcare data even when an organization’s principal clinical systems are not directly compromised.
See also: HIPAA Compliant Email: The Definitive Guide (2026 Update)
FAQs
How is data exfiltration different from unauthorized access?
Unauthorized access means someone entered a system without permission, while data exfiltration means information was copied or transferred out of that environment. An investigation may confirm unauthorized access without finding evidence that data was removed.
Does data exfiltration automatically constitute a HIPAA breach?
Not automatically, because the organization must determine whether protected health information (PHI) was involved and whether an exception applies. Confirmed exfiltration of unsecured PHI will generally require a documented HIPAA breach risk assessment and may trigger notification obligations.
Can attackers exfiltrate data without installing ransomware?
Yes, extortion groups increasingly steal information through compromised accounts and cloud applications without encrypting systems or deploying traditional ransomware.
