McKesson data theft and service disruption
Public report preview
McKesson discovered unauthorized access to third-party applications on August 25, 2026, and confirmed exfiltration of data associated with a subset of customers in its Oncology & Multispecialty and Medical-Surgical business units. Customers experienced intermittent service degradation, but McKesson said August 29 that they could use systems and services as intended while orders, distribution centers and shipping remained operational. ShinyHunters claimed responsibility and alleged a $55,236,150 data-extortion demand, but McKesson has not attributed the incident or confirmed ransomware deployment.
- Organization
- Location
Recent incident intelligence
Paid member report preview
Unlock the complete incident report
New reports are available immediately to Sustainers, after 2 weeks to Supporters, and to everyone once they are more than 1 month old.
Sustainers help fund the research and verification behind the Cyber Incident Registry while receiving immediate access to new reports.
See something that needs correction?
Signed-in members can report an error, update, or missing source.