"We have reasonable assurance of no ongoing unauthorized activity in our systems," Francisco Fraga, chief information and technology officer at McKesson, said in a statement.
McKesson's immediate response and operational status
McKesson disclosed on Friday that it had been the victim of a cyberattack that resulted in data theft and temporary service interruptions. The company said its business and distribution centers remain operational and that "customers can continue to connect to and use our systems and services as intended," Fraga added. McKesson also said it activated incident response protocols, launched an investigation, and engaged external cybersecurity experts after discovering the intrusion on Aug. 25.
McKesson did not identify a responsible group in its public comments and declined to answer reporters' questions about the attackers' claims or any ransom negotiations.
Scope of the intrusion and timeline researchers reported
According to the company, attackers gained access to some third-party applications and stole data associated with a subset of customers in McKesson’s oncology, multispecialty and medical-surgical business units. McKesson reported the discovery date as Aug. 25.
Independent researchers described a broader window of activity: they said a period of widespread data theft had concluded by the time McKesson discovered the incident, after a four-day intrusion beginning Aug. 21. On Friday, the company disclosed the attack in a regulatory filing while an external actor added McKesson to a public data-leak site.

The cyber insurance questionnaire just landed. Now what?
SOC 2, HIPAA, insurance renewals - someone has to own security strategy. Nubivance provides fractional CISO leadership without the full-time salary.
Get a security leadShinyHunters' claim, past campaigns, and tactics described by researchers
The decentralized cybercrime group ShinyHunters claimed responsibility and added McKesson to its data-leak site; McKesson declined to comment on that claim. Researchers and industry sources cited in reporting tie ShinyHunters to multiple previous campaigns against large cloud platforms, naming Oracle, Salesforce and Snowflake, and to a broad compromise of Salesloft Drift customers that affected integrations with an AI chat agent.
ShinyHunters was also linked to a disruptive April intrusion into Canvas, the education platform run by Instructure, that caused outages and data theft. When an early deadline passed without payment, ShinyHunters escalated pressure by defacing Instructure’s login pages with an extortion message visible to hundreds of schools; Instructure later said it reached an agreement with the cybercriminals and insisted the stolen data was returned with assurances other copies were destroyed. The FBI issued a public service announcement about ShinyHunters days after that episode.
Ian Gray, vice president of cyber threat intelligence at Flashpoint, summarized the group's recurring approach: it often uses social engineering or abuse of identity and access mechanisms to infiltrate cloud-hosted environments. "Opportunistic data extortionists have been able to identify weaknesses within identity and access management, making these campaigns both cheap and scalable," Gray said. He noted such intrusions can be hard to detect because they frequently use valid, socially engineered credentials and mimic normal support or data-warehouse tasks, avoiding traditional malware alerts and anomaly detection.
Pressure point: the ransom demand, a Sept. 1 deadline, and disclosure choices
While McKesson continues its investigation, ShinyHunters reportedly set a deadline of Sept. 1 and is seeking a ransom demand in excess of $55 million. McKesson did not answer questions about the alleged ransom demand or whether it had engaged with any extortionists.
The company’s public statements are narrow on remedies: they emphasize containment and ongoing investigation but stop short of confirming whether any negotiation, payment, or data recovery assurances have occurred. The juxtaposition of an imminent deadline and a major vendor's silence on next steps creates a compressed timeline for decision-making inside McKesson and for any affected customers watching for remediation or notification.
How technologists, affected health-care customers, and regulators are likely to react
- Technologists and security teams: expect scrutiny of identity and access management controls for vendor-hosted environments, since researchers say the group exploits valid credentials and cloud-hosted workflows that mimic normal tasks.
- Affected health-care customers in oncology, multispecialty, and medical-surgical units: will monitor McKesson’s forensic findings and notifications about what specific customer data were exposed and whether services remain fully available; McKesson has said distribution centers remain operational.
- Regulators and incident response bodies: may note the company’s public disclosure (including a regulatory filing) and will likely track whether a ransom demand is paid, whether extorted data are returned, and whether broader supplier risk controls need reinforcement — issues highlighted by the sector-wide warning Health-ISAC issued in late July about rising ShinyHunters activity.
McKesson is a large, high-profile target: the company says it distributes about one-third of all pharmaceuticals used throughout North America and reported $403.4 billion in revenue for the one-year period ending in March. That scale compounds the stakes for any query into whether stolen data are recoverable and how quickly affected customers are informed.
The immediate facts are narrow: an intrusion discovered Aug. 25, researchers' account of a four-day intrusion beginning Aug. 21, a public claim by ShinyHunters, and a reported ransom demand in excess of $55 million with a Sept. 1 deadline. McKesson’s public posture stresses containment and continued investigation, but the company has declined to address questions about the group’s claims or ransom negotiations — leaving open whether payment, recovery assurances, or further disclosures will follow.




