McKesson A.I CyberSecurity Scoring
McKesson
Company Information
Website:https://www.mckesson.com/about-us/?utm_source=linkedin&utm_medium=social&utm_campaign=company+profile
Employees number:25,352
Number of followers:611,876
NAICS:62
Industry Type:Hospitals and Health Care
Homepage:mckesson.com
McKesson Risk Score (AI oriented)
Between 700 and 749
McKessonHospitals and Health Care
Updated:
10/09/2026
10/09/2026
731/1000
Moderate
Ba
McKesson Global Score (TPRM)
xxxx
McKessonHospitals and Health Care
Score locked

McKessonModerate
Current Score
731Ba (MODERATE)
01000
3 incidents
-45.5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
730
AUGUST 2026
777
Breach
28 Aug 2026 • McKesson
McKesson Corporation and Salesforce: ShinyHunters claims McKesson data breach exposing 284 million patients
McKesson Hit by Massive Data Breach: ShinyHunters Claims Theft of 284M Patient Records
730
CRITICAL-47
SALMCK1787948754
McKesson Hit by Massive Data Breach: ShinyHunters Claims Theft of 284M Patient Records
The ShinyHunters threat group has claimed responsibility for a major cyberattack on McKesson Corporation, one of the largest U.S. healthcare distributors, alleging the theft of 284 million patient records containing highly sensitive medical, identity, and prescription data. CyberInsider reviewed samples provided by the threat actor, which appear consistent with the breach claims.
McKesson confirmed the incident in a statement, revealing that an investigation is underway into unauthorized access and data exfiltration via third-party applications. The company activated its incident response protocols, engaged cybersecurity experts, and is working to assess the scope and impact. No further details on the breach’s origin or timeline have been disclosed.
According to ShinyHunters, the stolen data includes:
- Patient records: Full names, addresses, Social Security numbers, medical histories (diagnoses, allergies, medications), hospice and terminal illness details, sexual orientation, and predictive health assessments (e.g., cancer risk).
- Prescription and billing data: Medication orders, invoices, shipment details, and tracking numbers.
- Healthcare provider information: Physician names, practice locations, clinic details, and employee records (including job roles and contact data).
- Communications: Email content between doctors and patients (excluding attachments).
The threat actors claim they gained access by voice-phishing two McKesson employees before extracting data from Salesforce and Snowflake instances. ShinyHunters is demanding a $55.2 million ransom to prevent the release of the stolen files but stated that McKesson has not responded to their demands.
The breach exposes patients and providers to heightened risks of identity theft, medical fraud, and targeted phishing attacks. McKesson’s investigation remains ongoing, with updates expected as more details emerge.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
820
Breach
01 Aug 2026 • McKesson
McKesson: Have I Been Pwned’s Post
McKesson Hit by ShinyHunters Extortion Campaign, 6.4M Emails Leaked
776
CRITICAL-44
MCK1789021407
McKesson Hit by ShinyHunters Extortion Campaign, 6.4M Emails Leaked
In a recent cybersecurity incident, healthcare giant McKesson was targeted in an extortion campaign by the threat actor group ShinyHunters last month. The breach resulted in the exposure of 6.4 million email addresses, including those from marketing campaigns, patients, and staff.
The leaked data was subsequently published, with 66% of the exposed emails already linked to LinkedIn profiles and third-party services. While the full scope of the breach remains under investigation, the incident highlights the ongoing risks of data extortion and the potential for widespread exposure of sensitive information.
McKesson, a major player in healthcare distribution and services, has not yet issued a detailed public statement on the breach’s impact or mitigation efforts. The incident underscores the persistent threat posed by cybercriminal groups like ShinyHunters, which frequently target large organizations for financial gain.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
JULY 2026
820
JUNE 2026
820
MAY 2026
819
APRIL 2026
819
MARCH 2026
819
FEBRUARY 2026
819
JANUARY 2026
819
DECEMBER 2025
818
NOVEMBER 2025
818
OCTOBER 2025
818
JANUARY 2025
833
Cyber Attack
01 Jan 2025 • McKesson
McKesson: McKesson confirms data theft in cyberattack involving third-party apps
McKesson Confirms Data Theft in Cyberattack Targeting Third-Party Cloud Applications
816
CRITICAL-17
MCK1788385186
McKesson Confirms Data Theft in Cyberattack Targeting Third-Party Cloud Applications
McKesson, a major U.S. healthcare distributor and supply chain backbone, has acknowledged a cyberattack involving unauthorized access to third-party cloud applications, resulting in data theft. The incident, claimed by the hacking group ShinyHunters, affected customers in McKesson’s oncology, multispecialty, and medical-surgical businesses. While the company has not confirmed the attackers’ statement nor independently verified the full scope of the breach it reported no disruption to its core distribution operations.
The attack aligns with a growing trend in healthcare cyber threats, where adversaries use social engineering, including voice phishing, to compromise employee accounts. Once inside, attackers exploit legitimate credentials to move undetected through systems, accessing sensitive data tied to the compromised user’s permissions. Scott Gee, deputy national adviser for cybersecurity at the American Hospital Association, noted that such activity often appears "normal," making detection difficult.
McKesson stated it has no evidence of ongoing unauthorized activity but has not determined whether the breach is material. The incident underscores the risks posed by healthcare intermediaries like McKesson and Change Healthcare, which serve as critical single points of failure due to their deep integration in billing, insurance preapprovals, and supply chains. Unlike the 2024 Change Healthcare ransomware attack which caused weeks of operational paralysis McKesson’s breach highlights the stealthy nature of account takeovers and their potential to extract data without immediate disruption.
The full impact on affected individuals remains unclear, but the attack reflects broader vulnerabilities in healthcare’s reliance on interconnected third-party platforms.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for McKesson ??
What was McKesson's A.I Rankiteo Cyber Score in August 2026 ??
What was McKesson's A.I Rankiteo Cyber Score in July 2026 ??
What was McKesson's A.I Rankiteo Cyber Score in June 2026 ??
What was McKesson's A.I Rankiteo Cyber Score in May 2026 ??
What was McKesson's A.I Rankiteo Cyber Score in April 2026 ??
What was McKesson's A.I Rankiteo Cyber Score in March 2026 ??
What was McKesson's A.I Rankiteo Cyber Score in February 2026 ??
What was McKesson's A.I Rankiteo Cyber Score in January 2026 ??
What was McKesson's A.I Rankiteo Cyber Score in December 2025 ??
What was McKesson's A.I Rankiteo Cyber Score in November 2025 ??
What was McKesson's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on McKesson's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with McKesson ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view McKesson's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?