Doctor with laptop showing patient records data breach

Data Breach Hits Medical Supply Chain Giant McKesson, Exposing 284 Million Patient Records

Healthcare information technology company McKesson has notified victims and federal regulators of a data breach that leaked millions of patient records.

According to a regulatory filing with the U.S. Exchange Commission, McKesson learned of the cyber incident in late August. It responded by launching an investigation with third-party cybersecurity experts, which determined that the healthcare giant was the victim of a cyber attack.

“On August 25, 2026, McKesson became aware that it had been the subject of a cybersecurity incident targeting employee corporate accounts,” the company wrote.

McKesson data breach leaks millions of patient records

Preliminary results of the investigation determined that the data breach leaked protected health information (PHI). However, the healthcare giant has not disclosed the nature of the stolen patient records.

“Because McKesson works as a vendor to health care providers, personal information, including protected health information, may have been impacted in this incident,” it stated.

While McKesson has not disclosed the impacted vendor, it linked the data breach to third-party applications. According to a statement on its website, the data breach affected Oncology & Multispecialty and Medical-Surgical business units.

Meanwhile, McKesson has not determined whether the data breach will have a material impact on its financial condition or disrupt its operations.

“As of the date of this filing, the company has not determined that the incident is material or that the incident has had, or is reasonably likely to have, any material impact on the company, including its financial condition or results of operations,” the company stated.

However, the company warned that its customers would experience intermittent disruptions and service degradation, but ruled out disconnecting from the affected third-party vendor’s environment. The company also said its operations continued to run normally and that no malicious activity has been detected in its environment.

At the time of publication, McKesson has not disclosed the identity of the threat actor or how they gained access. Similarly, the company has yet to disclose the number of affected individuals.

However, the healthcare giant is offering complimentary identity theft protection services to shield the victims from fraud.

“The McKesson incident is another reminder that an organization’s attack surface extends well beyond the systems it directly controls,” said Phil Wylie, Senior Consultant & Evangelist, Suzu Labs. “Third-party applications with access to sensitive data can provide attackers with a path around otherwise mature security controls.”

“The potential impact is especially concerning in healthcare. When an organization sits at the center of the pharmaceutical and medical supply chain, a cyberattack is no longer just a data-security issue. Disruption can potentially ripple downstream to providers, pharmacies and ultimately patients,” added Wylie.

ShinyHunters claims McKesson data breach

The prolific hacking group ShinyHunters has taken responsibility for the McKesson data breach. The group claims to have gained access after targeting the company’s employees via social engineering attacks and breaching Okta single sign-on accounts.

Upon gaining access, the hacking group pivoted to the company’s Salesforce and Snowflake accounts and exfiltrated millions of patient records. The group claims it stole 1 terabyte of data containing 284 million patient records from the company’s Snowflake environment.

Although the group has yet to analyze the stolen patient records, it claims the trove included both personally identifiable information and protected information. Personal details allegedly exposed include names, addresses, dates of birth, Social Security numbers, phone numbers, and email addresses.

Additionally, the group accessed health information including patient IDs, medical record numbers, Medicaid numbers, medications, allergies, illnesses, disabilities, appointments, and physician information.

Other details exposed included invoices, employee information, and the names of healthcare providers working with McKesson. Billing information, such as medication orders, invoice numbers, shipping addresses, and tracking details, was also exposed.

ShinyHunters also claims that the leaked patient records exposed information about the deceased and terminally ill patients, prescriptions, internal hospital communications, hospice information, autopsy details, sexual orientation, and disease risk assessments. The group demanded $55,236,150 to avoid publishing the stolen patient records on the dark web.

Various industry sources have confirmed the authenticity of some of the leaked patient records, but McKesson has not. However, even ShinyHunters has yet to confirm the number of victims. McKesson’s spokesperson also says the company’s investigation is still ongoing and that it will provide an update when it becomes available.

“When a third-party application breach hits a healthcare supply chain giant like McKesson, a single vendor integration can escalate into a national patient data crisis,” warned Damon Small, Board of Directors, Xcape. “The claim that 284 million records were exfiltrated is alarming, even if core delivery operations remain online.”