Blog > Data Breach & Privacy

McKesson Data Breach: What Patients and Customers Need to Know

McKesson, one of the largest healthcare and pharmaceutical distributors in the country, confirmed a cybersecurity incident involving unauthorized access to certain third-party applications and the exfiltration of data. A threat actor has claimed patient records were taken. Here is what has been confirmed and what it may mean.

McKesson Data Breach: What Patients and Customers Need to Know

What Happened in the McKesson Data Breach

A confirmed cybersecurity incident involving third-party applications

According to a disclosure McKesson made in a Form 8-K filing with the U.S. Securities and Exchange Commission, the company reports that it discovered a cybersecurity incident on or about August 25, 2026, involving unauthorized access to certain third-party applications and the exfiltration of certain data. In public statements, McKesson has said that, upon discovery, it activated its incident response protocols, launched an investigation, and engaged leading cybersecurity experts, and that the investigation remains in its early stages.

Reporting on the incident indicates that the unauthorized access and data exfiltration may have been associated with a subset of customers within McKesson’s Oncology & Multispecialty and Medical-Surgical business units. As of these initial disclosures, McKesson had not publicly detailed the full scope of the incident, including exactly which data was affected or how many individuals may be involved, and additional details reported at this stage may change as the investigation continues.

What Information May Have Been Involved

What McKesson has confirmed and what remains unverified

At this stage, McKesson has confirmed that unauthorized access to certain third-party applications occurred and that certain data was exfiltrated, but the company has not publicly itemized the specific categories of information involved or confirmed a total number of affected individuals. It is important to separate what the company has confirmed from claims made by others.

A threat actor group known as ShinyHunters has claimed that the stolen data includes personal and health-related information. Those claims have not been independently verified, and McKesson has not publicly confirmed the specific data types or volume attributed to the threat actor. Where personal or health information may potentially be involved in an incident of this kind, there can be an increased risk of identity theft, medical identity theft, fraud, or targeted phishing, which is why affected individuals may wish to stay alert even while the facts are still being established.

Who May Be Affected by the McKesson Breach

Patients and healthcare organizations connected to McKesson

McKesson is one of the largest healthcare services and pharmaceutical distribution companies in the United States, working with a wide range of healthcare providers, pharmacies, and health systems. Because the incident has been reported to involve a subset of customers within certain business units, the individuals potentially affected could include patients and organizations connected to the affected McKesson services, though the company has not published a confirmed list or count.

Given McKesson’s scale, many people may be understandably concerned about whether their information could be involved. At this stage, the most reliable path is to watch for official communications from McKesson or from a healthcare provider or pharmacy you work with, rather than relying on claims circulating from the threat actor.

Understanding the ShinyHunters Claims

Why the reported "284 million records" figure needs context

Much of the coverage of this incident references a figure of approximately 284 million records, which comes from the ShinyHunters threat actor group rather than from McKesson. According to reporting, ShinyHunters has clarified that this number reflects a raw count of data records or lines, not a count of unique individuals — meaning the number of actual people potentially affected could be very different and has not been confirmed.

Reporting also attributes to the threat actor specific claims about how the incident occurred, including the use of voice phishing to compromise employee credentials and access to platforms such as Salesforce and Snowflake. These are allegations from the threat actor and reporting on the incident; they have not been confirmed by McKesson. Treating these figures and methods as unverified claims — rather than established facts — is the most accurate way to understand the situation as it develops.

Steps You Can Take to Protect Yourself

Practical precautions while the investigation continues

While the scope of the McKesson incident is still being investigated, taking a few precautionary steps may help you reduce risk:

  • Watch for official notifications. If your information is confirmed to be involved, you may receive a notice from McKesson or a related healthcare provider or pharmacy explaining your options.
  • Review your accounts and Explanation of Benefits statements. Watch for unfamiliar charges, medical claims, or services you did not receive, which can be a sign of medical identity theft.
  • Check your credit reports. You are entitled to free annual credit reports at annualcreditreport.com, and you can watch for accounts or inquiries you do not recognize.
  • Consider a fraud alert or credit freeze. These are available at no cost through Equifax, Experian, and TransUnion and can add a layer of protection.
  • Stay alert to phishing. Incidents that receive heavy news coverage are often followed by scams. Be cautious of unexpected emails, calls, or texts referencing the breach, and verify communications through official channels before sharing information.

This information is a general overview and is not legal advice; your situation may differ, and consulting a legal professional can help you understand rights that may apply to you.

Talk to Wilshire Law Firm

Concerned about the McKesson data breach?

If you believe your personal or health information may have been involved in the McKesson data breach, do you know what your options are? Our nationally recognized, award-winning team is here to help you understand your rights. Wilshire Law Firm offers free consultations and free case reviews with a legal professional, and we are available 24/7. Because we work on a contingency basis, there are no fees unless you get paid.

Contact Wilshire Law Firm today to schedule your free case review and get your questions answered.

FAQs

McKesson has reported that it discovered a cybersecurity incident on or about August 25, 2026, involving unauthorized access to certain third-party applications and the exfiltration of certain data. The company disclosed the incident in a filing with the U.S. Securities and Exchange Commission and has said its investigation is ongoing.

McKesson has confirmed that it experienced a cybersecurity incident involving unauthorized access to certain third-party applications and that certain data was exfiltrated, and that it activated its incident response and engaged cybersecurity experts. The company has not publicly confirmed the specific data types involved or the number of individuals affected.

Details about how the incident occurred — including claims involving voice phishing of employees and access to platforms such as Salesforce and Snowflake — come from the ShinyHunters threat actor group and reporting on the incident, and have not been confirmed by McKesson.

McKesson has not publicly itemized the specific data involved. A threat actor group has claimed the stolen data includes personal and health-related information, but those claims have not been independently verified or confirmed by McKesson.

A confirmed number of affected individuals has not been published. The widely reported figure of approximately 284 million comes from the ShinyHunters threat actor and reportedly reflects a raw count of data records or lines, not unique individuals, so the number of actual people affected is not yet known.

Watch for official notifications from McKesson or a related healthcare provider or pharmacy, monitor your financial accounts, credit reports, and Explanation of Benefits statements, stay alert to phishing, and keep any notice you receive. You may also wish to speak with a legal professional about any rights or options that may apply to your situation.

Individuals who are confirmed to be affected may have legal options, and large data breaches involving personal or health information can sometimes lead to class action litigation. Whether a claim may apply to you depends on the specific facts as they are established. A free case review with a legal professional can help you understand your potential rights.

Related Content

Guides, nearby offices, and related practice areas.

Start Your Free Case Review

4.9 out of 2,500+ reviews
  • Available 24/7
  • Hablamos Español
  • Nationally-Recognized Powerhouse Team
As seen in:

We'll contact you within minutes

No fees unless you get paid.

By submitting this form, you knowingly, voluntarily, and expressly consent to receive from Wilshire Law Firm telephone calls, emails, and SMS text messages, including those made using an automatic telephone dialing system (auto-dialer), artificial intelligence (AI), and/or pre-recorded or artificial voice messages. These communications are for the purpose of providing prompt consultation regarding your potential case. You understand that by providing your telephone number, you are granting permission to be contacted for this purpose, even if your number is on a federal or state Do-Not-Call registry. Consent is not required as a condition of retaining Wilshire Law Firm. Message and data rates may apply. You may revoke your consent to receive calls, texts, or emails at any time by replying “STOP” to any text message, calling 888-557-3271, filling out the form at wilshirelawfirm.com/do-not-contact or by any other reasonable method. For more information, refer to our Privacy Policy.

Locations

Find your nearest office — serving all of California and employment clients in Oregon and Washington.

Appointments required for office visits

Beverly HillsIrvineLos AngelesOaklandRiversideSacramentoSan DiegoTorrance