U.S. healthcare distributor McKesson has disclosed a cyber incident involving several cloud-based accounts, with attackers reportedly accessing sensitive information tied to its oncology, multispecialty, and medical-surgical operations.
The Texas-based company said the breach may cause intermittent service disruptions as it works through the response process. McKesson also noted that the incident involved data stored in cloud environments used across parts of its healthcare business.
According to the hacking group ShinyHunters, the intrusion was carried out through phishing and social engineering tactics aimed at employees. The group claims it obtained names, addresses, Social Security numbers, and protected health information such as diagnoses, medications, allergies, and patient notes.
The attackers also say they accessed millions of rows of data from cloud systems linked to Snowflake and Salesforce, though the full number of affected individuals has not been confirmed. Employee details, including home addresses, were also reportedly among the files taken.
McKesson is one of the largest pharmaceutical and medical supply distributors in the United States, making it a central player in the digital infrastructure of healthcare. The case adds to a broader wave of cyber incidents affecting medical companies and patient-data platforms in recent months.
As healthcare continues to expand its cloud footprint, stronger identity controls and data protection standards are likely to become even more central to the future of digital medicine.