Drug distribution giant McKesson suffers a cyberattack as hackers claim data theft and demand a massive $55 million ransom.
Healthcare and drug distribution giant McKesson has suffered a major cyberattack that disrupted some of its online computer services and exposed private customer records.
Unknown cybercriminals broke into external software programs used by the business to manage customer details and medical sales records.
Once inside, the hackers copied and stole sensitive electronic files before demanding a massive cash payment. Because McKesson supplies roughly onet hird of all prescription medicine across North America, the digital break in immediately raised widespread alarm over potential delays in delivering life saving medical supplies to hospitals, doctor clinics, and neighborhood pharmacies.
The serious technology incident was officially confirmed in government filings and public company statements published on Friday, August 28, 2026, with further updates provided on Monday, August 31, 2026.
Digital investigators tracked the initial unauthorized entry back to Tuesday, August 25, 2026, after security systems flagged unusual activity inside third-party application networks.
Shortly after the discovery, a well known cybercrime syndicate called ShinyHunters claimed responsibility for the attack, posting online messages that they had stolen approximately one terabyte of confidential files and roughly 284 million patient-related records.
The primary reason this attack happened is that internet thieves used deceptive phone calls, a trick called voice phishing, to trick company employees into handing over their secure login passwords.
See Also: Fortinet Launches Free High School Cybersecurity Curriculum to Build Next-Generation Cyber Defenders
By impersonating official helpdesk technicians, the hackers stole valid employee credentials and used them to quietly walk past normal security checkpoints.
Once logged in, the bad actors accessed cloud systems containing customer files from the company’s surgical and cancer treatment business divisions.
The criminal group then demanded a huge 55 million dollar ransom payment to delete the stolen files and refrain from posting private records online.
Explaining how the digital attack disrupted computer operations for some customers, McKesson Chief Technology Officer Francisco Fraga said in an official statement, “At this time, customers may experience intermittent service degradation that we believe may be related to this incident”.
Detailing how company managers are actively watching network systems to prevent further harm, Francisco Fraga added, “We are aware of these issues and continue to monitor the situation closely”.
Reassuring customers that security teams had pushed the intruders out of company networks and that daily operations could safely continue, Francisco Fraga noted, “Customers can continue to connect to and use our systems and services as intended”.
Promising to protect individuals whose personal details may have been copied by the internet thieves, company executives confirmed that they would provide free credit monitoring and identity protection services to affected clients.
By taking fast action to secure affected networks and provide free credit protection, McKesson is working hard to fix the breach.
Teaching workers to spot fake phone calls and keeping server controls updated ensures that critical medical supplies keep moving safely to patients across the country.

