PUBLISHED Aug 31, 2026, 10:36 AM ET
Healthcare and pharmaceutical distributor McKesson disclosed a cybersecurity incident on August 31, 2026, involving unauthorized access to and data exfiltration from a third-party application [citation:8]. The company filed an 8-K with the SEC, stating the intrusion was detected on August 25 and is under investigation [citation:3]. Cybercriminal group ShinyHunters claimed responsibility, asserting they stole approximately 284 million data rows—roughly one terabyte—between August 21 and 25 [citation:3][citation:5]. The group reported using voice phishing to compromise employee Okta accounts, gaining access to Salesforce and Snowflake environments [citation:5][citation:7]. An extortion demand exceeding $55 million has been issued, with a deadline of September 1 [citation:1][citation:5]. McKesson warned that customers in its Oncology & Multispecialty and Medical-Surgical units may experience service degradation but stated it has not yet determined the incident to be financially material [citation:1][citation:7]. The compromised data allegedly includes sensitive patient information such as Social Security numbers and medical records [citation:2][citation:4]. The company is working with external cybersecurity experts and has established a dedicated information page at mckesson.com/cybersecurity [citation:3][citation:8].
By Daniel Hayes | JQJO News
Left: Left-leaning framing emphasizes patient privacy violations and the need for stronger corporate data protection [citation:2] Center: Neutral framing focuses on the confirmed breach details, company response, and the alleged hacker claims [citation:1][citation:3] Right: Right-leaning framing likely questions the necessity of new regulations and highlights the business response to the attack [citation:1]
McKesson filed an SEC 8-K on Aug 28, 2026, disclosing a cyber incident [citation:3] https://www.mckesson.com/utility/cybersecurity/customer-cybersecurity-information-center/
No left-leaning sources found for this story.
Healthcare Giant McKesson Hit by Massive Cyberattack
JQJO SecurityWeek BleepingComputer The Record from Recorded Future News Help Net Security The HIPAA Journal Check Point Research CyberInsider Cloaked Ademi & Fruchter LLP 安全内参 (Secrss) MalloryNo right-leaning sources found for this story.
Comments