Skip to content
Color theme
Back to intake

Verified incident record

What McKesson has confirmed—and what remains unknown

The investigation is new. This record keeps company-confirmed facts separate from unverified reporting.

01

Discovery and disclosure

McKesson's Form 8-K says the company discovered a cybersecurity incident affecting its information systems on August 25, 2026. McKesson disclosed it publicly on August 28, 2026 under Item 7.01, Regulation FD.

02

What McKesson confirmed

McKesson's customer update says the incident involved third-party applications, unauthorized access, and data exfiltration. The company said its investigation was ongoing and that some customers could experience intermittent service degradation.

03

What McKesson has not disclosed

McKesson has not publicly identified the affected applications, access method, information involved, affected organizations, or number of affected people. Its 8-K says the company had not determined, as of filing, that the incident was material or likely to have a material effect on the company.

04

Unverified threat-actor claims

BleepingComputer reports that ShinyHunters claims it accessed cloud platforms and stole patient-related data. A widely repeated figure of about 284 million is described as raw database records or rows—not unique people. McKesson has not confirmed the actor, technical details, figure, or claimed data categories.