McKesson Breach Hits Third-Party Apps

McKesson disclosed on Aug. 25 that unauthorized access hit third-party applications, and ShinyHunters separately claimed it stole 284 million patient records. The company said it found the incident that day and filed an SEC Form 8-K while its investigation remained in the early stages. McKesson said the intrusion involved unauthorized access and exfiltration from applications it does not describe as part of its core environment. In plain terms, that puts the compromise point in vendor-connected systems and the data they already held or could reach, which can leave service degradation and disclosure obligations in place even if McKesson’s internal network is not fully taken down. For healthcare providers, pharmacies, and other partners that feed or receive data through those applications, the exposure may sit in the shared data path rather than inside McKesson alone. The report does not yet say which applications were touched or what data was taken, so the downstream blast radius is still unsettled.

Part of the PlainSec briefing for 2026-08-29

Every edition of this story: McKesson Breach Hits Third-Party Apps

Sources