Cryptelio

Hacks & Exploits

McKesson Confirms Cloud Breach Exposing Patient Records Amid Ransom Demand

Cryptelio Editorial Published 1 Sep 2026 · 11:00 UTC

McKesson, a Texas-based pharmaceutical distributor, has confirmed unauthorized access to its cloud systems, resulting in a significant data breach. The incident, discovered on August 25, involved unauthorized access to third-party applications, affecting a subset of customers in its oncology and multispecialty division, as well as its medical-surgical unit.

The extortion group ShinyHunters claims to have gained access through vishing calls that tricked employees into revealing Okta single sign-on credentials. They allege that approximately 284 million patient-record lines and about one terabyte of data were exfiltrated between August 21 and 25, and have set a deadline of September 1 for a $55 million ransom to avoid public disclosure of the data.

While McKesson has not confirmed the exact number of records or the types of data involved, the company has filed an SEC Form 8-K and is planning to offer credit monitoring and identity protection services to affected individuals. McKesson asserts that it has reasonable assurance of no ongoing unauthorized activity and continues to operate all lines of business.

FAQ

What happened in the McKesson data breach?

McKesson confirmed unauthorized access to its cloud systems, resulting in a significant data breach that affected a subset of customers in its oncology and multispecialty division, as well as its medical-surgical unit.

How did the breach occur?

The extortion group ShinyHunters claims to have gained access through vishing calls that tricked employees into revealing Okta single sign-on credentials.

What data was compromised in the breach?

Approximately 284 million patient-record lines and about one terabyte of data were allegedly exfiltrated, although McKesson has not confirmed the exact number of records or types of data involved.

What actions is McKesson taking in response to the breach?

McKesson has filed an SEC Form 8-K and is planning to offer credit monitoring and identity protection services to affected individuals.

Is there any ongoing unauthorized activity related to the breach?

McKesson asserts that it has reasonable assurance of no ongoing unauthorized activity and continues to operate all lines of business.

Read story →