McKesson confirms data theft in cyberattack involving third-party apps
Drug distributor McKesson confirmed a cyberattack where an unauthorized actor accessed third-party applications and stole data from oncology, multispecialty, and medical-surgical customers. While McKesson reports no ongoing unauthorized activity and normal operations, the hacking group ShinyHunters claimed responsibility, alleging they used voice phishing to compromise employee accounts. The incident highlights growing cyber risks for deeply embedded healthcare intermediaries.
McKesson data breach incident
▪McKesson stated that it has reasonable assurance there is no ongoing unauthorized activity related to the cyberattack on its third-party applications.
▪Drug distributor McKesson confirmed that an unauthorized person gained access to its third-party applications and stole data affecting oncology, multispecialty, and medical-surgical customers.
▪McKesson stated in a securities filing that its businesses and distribution network remain operational, and the company has not determined if the cyberattack is material.
Voice phishing attack method
▪Scott Gee of the American Hospital Association stated that voice phishing attacks are difficult to detect because compromised employee account activity often appears legitimate.
▪The hacking group ShinyHunters claimed to have used voice phishing to compromise McKesson employee accounts and access cloud applications, though McKesson has not confirmed this statement.
ShinyHunters threat group
▪The hacking group ShinyHunters claimed responsibility for the McKesson data breach, telling BleepingComputer that they accessed patient data.
▪The Health Information Sharing and Analysis Center reported in July 2026 that the ShinyHunters hacking group was increasingly targeting single-sign-on accounts and cloud applications.
Healthcare supply chain cyber risk
▪Scott Gee of the American Hospital Association characterized the 2024 Change Healthcare ransomware attack as a single point of failure, contrasting its operational collapse with the McKesson incident.
▪McKesson operates as a major logistical backbone of the healthcare industry, making approximately 40,000 deliveries daily to care sites nationwide.
Single sign-on compromise pattern
▪The Health Information Sharing and Analysis Center warned in July 2026 that cybercriminals are using voice phishing to take over single-sign-on accounts and compromise connected cloud applications.
▪AdaptHealth disclosed in July 2026 that a cybercriminal used social engineering to access cloud-based applications and steal patient health information, illustrating a similar compromise pattern.
Story comments
Loading comments…