McKesson Data Breach Exposes Patient Information After Cloud Attack

McKesson confirms a cloud security breach after hackers claim to have stolen millions of patient records, including sensitive health data.

Aug 31, 2026 - 14:49
 3
McKesson Data Breach Exposes Patient Information After Cloud Attack
Image Credit: TechAmerica.ai / AI-generated image

McKesson, one of the largest pharmaceutical distributors in the United States, has confirmed a cyberattack after hackers claimed to have stolen millions of patient records from the company’s cloud environment.

McKesson said attackers accessed several cloud-hosted accounts and removed data from its systems. The company warned customers that some services could experience intermittent disruptions related to the incident.

Hackers Claim Theft of Sensitive Healthcare Data

The ShinyHunters hacking group claimed responsibility for the attack, saying it gained access through phishing and social engineering techniques targeting employees. The group said it obtained data from McKesson’s cloud-hosted environments, including systems connected to Snowflake and Salesforce.

The attackers claimed that the stolen information includes names, addresses, Social Security numbers, and protected health information such as diagnoses, medications, allergies, and patient notes. They said the breach involved millions of rows of data but could not confirm how many individuals were affected.

McKesson said the affected information relates to its oncology, multispecialty, and medical-surgical business units. The company also said employee information, including home addresses, was among the potentially exposed data.

Healthcare Sector Faces Continued Cybersecurity Pressure

BleepingComputer reported that the attackers demanded a $55 million ransom in exchange for not publishing the stolen files. McKesson has not confirmed the ransom demand.

The incident follows a series of cyberattacks targeting healthcare companies and medical technology providers, in which criminals have focused on sensitive medical information for extortion.

ShinyHunters has previously claimed responsibility for major healthcare-related breaches, including incidents involving Amazon-owned One Medical and dental insurance provider DentaQuest.

Other healthcare organisations have also reported significant cyber incidents in recent months, increasing concerns about the protection of patient data across the medical industry.

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0
Shivangi Yadav Shivangi Yadav’s current bio says she reports on technology-focused developments “in India”, but the same profile publishes stories about U.S. NHTSA investigations, Hugging Face, global AI startups and other international topics.