A hacking group has claimed responsibility for a cyberattack against McKesson, a major U.S. pharmaceutical distribution company, which occurred last week. McKesson confirmed on August 31, 2026, that hackers accessed several of its cloud-hosted accounts and exfiltrated sensitive data. The company anticipates "intermittent service degradation" due to the incident. According to McKesson's chief technology officer, Francisco Fraga, the compromised data pertains to its oncology & multispecialty and medical-surgical units.
McKesson, based in Texas, is one of the largest distributors of pharmaceuticals and medical supplies in the U.S., managing significant amounts of patient data. The ShinyHunters hacking group, known for its data-extortion tactics, reported that it gained access to McKesson's network through phishing and social engineering methods.
The hackers claimed to have stolen personal information, including names, addresses, Social Security numbers, and protected health information such as diagnoses and medications. They stated that millions of patient records were taken from McKesson's cloud-hosted environments, although they could not confirm the exact number of individuals affected. Additionally, information about McKesson employees, including home addresses, was also compromised.
Screenshots and a sample of the stolen data were shared with TechCrunch, which verified a portion of the data against public records. Bleeping Computer reported that the hackers demanded a ransom of $55 million from McKesson to prevent the public release of the stolen files.
In response, McKesson spokesperson Kristina Chang stated that the company continues to operate across all business lines and believes there is no ongoing unauthorized activity within its systems. However, the company did not disclose details regarding the ransom demand or the number of individuals affected.
This incident marks another in a series of cyberattacks targeting healthcare companies, as hackers increasingly seek to exploit sensitive medical data for ransom. Recent attacks have also impacted Boston Scientific, Stryker, Abbott Laboratories, and Medtronic, among others. The ShinyHunters group has previously claimed responsibility for breaches at One Medical and DentaQuest.