Incident
Published 2026-08-28
Verified 2026-09-19

McKesson: cybersecurity incident with third-party apps and data exfiltration

McKesson's 28 August 2026 customer notice and Form 8-K say it discovered a cybersecurity incident on 25 August 2026 affecting its information systems. The company says the investigation is in early stages and involves third-party applications plus unauthorised access and exfiltration of data. Updates are posted at mckesson.com/cybersecurity. A 29 August 2026 customer note on that page (heading: McKesson Cybersecurity Incident Investigation and Response Update) says McKesson continues to serve customers across all lines of business and accept orders, distribution centres remain operational, and shipping continues. That note does not add scope, named applications, or confirmation of actor claims. As of the 8-K filing date, McKesson had not determined the incident to be material or reasonably likely to have a material impact on financial condition or results of operations. The company has not publicly named the applications involved, the access path, or what was taken. Secondary reporting attributes claims by the ShinyHunters extortion group (including a large patient-record count and Okta/Salesforce/Snowflake access via vishing); those actor claims are not confirmed in McKesson's notice or 8-K and are not treated as verified facts on this desk.

Exploited in Australia?
unknown

Primary: McKesson cybersecurity notice ยท McKesson Form 8-K (28 Aug 2026)

breaches healthcare