McKesson disclosed a data breach involving unauthorized access to third-party applications and data exfiltration, placing a major distributor in the U.S. healthcare supply chain under scrutiny. The Irving, Texas-based company discovered the cybersecurity incident on August 25 and filed a Form 8-K with the U.S. Securities and Exchange Commission on August 28. Its investigation remains in an early stage.

McKesson supplies medicines, medical products, technology and services to healthcare providers and pharmacies. In its SEC filing, the company said it had not determined that the incident was material or reasonably likely to materially affect its finances or operations as of the filing date. A separate customer notice said McKesson activated incident-response procedures and engaged outside cybersecurity specialists after discovery.

The company confirmed that an intruder accessed third-party applications and removed data, but it has not identified the applications, explained the initial access method or described the stolen information publicly. McKesson also warned customers of intermittent service degradation that it believes is related to the incident, while stating that it was not proactively disconnecting systems in its environment.

ShinyHunters claimed responsibility in statements to BleepingComputer and alleged that voice phishing against employees led to compromised Okta single sign-on accounts and access to Salesforce and Snowflake. The group also claimed it removed about one terabyte of data from August 21 through August 25. McKesson has not confirmed that account, and BleepingComputer said it could not independently verify the claims.

The attackers further alleged that the stolen material contains roughly 284 million patient-related records. That figure is a claimed count of database rows, not a verified number of unique patients, and the group acknowledged that it had not established how many individuals were represented. McKesson has not confirmed the volume or categories of exposed data, making any estimate of affected people premature.

Health-ISAC has separately warned healthcare organizations that ShinyHunters uses voice phishing and helpdesk manipulation to seize identity accounts and reach connected cloud services. Its defensive guidance includes verified callbacks for reset requests, phishing-resistant multifactor authentication, tighter controls on new authentication factors, centralized identity and SaaS logs, and monitoring for unusual downloads or OAuth grants. McKesson said it will provide updates as its understanding of the breach develops.