Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million patient data records.

McKesson is a major U.S. healthcare company and pharmaceutical distributor that provides medicines, medical supplies, technology, and services to healthcare providers and pharmacies.

CyberInsider first reported the breach earlier today, and McKesson later disclosed it in a Form 8-K filing with the U.S. Securities and Exchange Commission.

McKesson says it discovered the cybersecurity incident on August 25, 2026, and that its investigation remains in the early stages.

"Information about the incident, including any updates, is available on the company's website at www.mckesson.com/cybersecurity," McKesson said in its SEC filing.