Investigation · Healthcare Data

McKesson Data Breach Investigation

You may have never knowingly dealt with McKesson. Its businesses can operate behind prescription approvals, medication-affordability programs, and specialty-pharmacy care. Use the checklist below to look for a possible connection—but remember that no connection, by itself, confirms that your information was involved in this incident.

McKesson discovery date
Aug. 25

2026 date reported in McKesson's SEC filing

Actor-claimed records
~284M

raw lines, not unique people; unverified by McKesson

Affected people
Not confirmed

McKesson's investigation remains ongoing

Could this be me?

Could McKesson have my information?

Possibly—even if you do not recognize the company name. McKesson identifies CoverMyMeds and Biologics by McKesson as businesses that support medication access, affordability, prior authorization, and specialty-pharmacy care. A provider, pharmacy, health plan, or drug manufacturer may have interacted with one of those services during your care.

  1. A prescription needed prior authorization

    CoverMyMeds is a McKesson business whose electronic prior-authorization tools connect providers, pharmacies, health plans, and patients. A prior-authorization delay is a clue worth checking, although many systems process these requests.

    • “Your insurance denied the prescription.”
    • “We are waiting on prior authorization.”
    • “Your doctor needs to submit paperwork to insurance.”
  2. You used CoverMyMeds

    This is one of the clearer ways to identify a possible McKesson relationship. Look for a CoverMyMeds account, email, text, portal message, prior-authorization key, support exchange, or medication-access record.

  3. Biologics by McKesson filled or managed a prescription

    Biologics by McKesson is a specialty pharmacy. McKesson says it offers more than 200 oncology and rare-disease therapies and supports cell and gene therapy. A Biologics label or record is a stronger connection—but still does not prove breach inclusion.

    • Examples on its August 2026 list include Actemra, Benlysta, Brukinsa, Cabometyx, Calquence, Casgevy, Erleada, Gleevec, and Jakafi.
  4. You received specialty-medication access or cost support

    McKesson's CoverMyMeds and Biologics materials describe services involving medication affordability, copay help, financial assistance, benefits review, prior authorization, reimbursement, and access support. Search for the drug or manufacturer program name too; McKesson may not have been the most visible name.

    • Copay or financial assistance
    • Benefits investigation or insurance verification
    • Prior-authorization or appeals support
    • Reimbursement or specialty-access support
  5. You received oncology, rare-disease, or other complex therapy

    Biologics by McKesson focuses on oncology, rare disease, and cell and gene therapies. If your care team coordinated insurance approval, specialty-pharmacy delivery, financial assistance, or manufacturer support, check the related records for a McKesson business name.

  6. A specialty pharmacy shipped medication to you

    Check old prescription bottles, shipment labels, packing slips, emails, texts, patient portals, and payment records. Direct paperwork naming Biologics by McKesson is more useful than the type or price of the medication alone.

    • McKesson
    • Biologics by McKesson
    • CoverMyMeds

Check your records

Start with a three-term search

Search email, text messages, patient portals, and saved documents for these names, then preserve any dated result that shows how the service related to your care.

McKessonCoverMyMedsBiologics
  • Check old prescription bottles, shipment paperwork, and specialty-pharmacy records.
  • Review prior-authorization, copay, patient-assistance, and insurance-approval messages.
  • Keep original records and dates; do not send medical records or identification through an ordinary contact form.

Answer at a glance

What has McKesson confirmed about the incident?

McKesson disclosed in an August 28, 2026 Form 8-K that it discovered a cybersecurity incident affecting its information systems on August 25. In a separate customer notice, the company confirmed that the incident involved third-party applications and unauthorized access and exfiltration of data.

BleepingComputer reports that ShinyHunters claimed responsibility and alleged access to Salesforce and Snowflake after voice-phishing employees. McKesson has not confirmed the actor, access method, affected applications, data categories, or number of affected people.

This is an investigation, not a filed lawsuit by Hall Attorneys. Facts may change as organizations, regulators, courts, or security researchers publish additional information.

  1. Threat actor claims four days of data theft

    ShinyHunters told BleepingComputer that it exfiltrated about one terabyte of data during this period. McKesson has not publicly confirmed that timeline or volume.

  2. McKesson discovers the incident

    McKesson's Form 8-K identifies August 25 as the discovery date. The company says it activated its response protocols and began investigating with outside cybersecurity experts.

  3. Company and SEC disclosures published

    McKesson filed its Form 8-K and published a customer notice confirming unauthorized access and data exfiltration involving third-party applications. BleepingComputer separately reported the ShinyHunters claims.

Reported data categories

What information was involved?

McKesson has not publicly identified the information involved. The categories below come from ShinyHunters' claims as reported by BleepingComputer and have not been independently verified or confirmed by McKesson.

Important distinction

The approximately 284 million figure is an alleged count of raw records or lines, not unique patients. ShinyHunters told BleepingComputer that it had not fully analyzed the data and did not know the number of unique people represented.

Identity and contact
Names, addresses, birth dates, Social Security numbers, phone numbers, and email addresses allegedly involved
Healthcare identifiers
Patient IDs, medical-record numbers, and Medicaid numbers allegedly involved
Medical information
Medications, allergies, illnesses, disabilities, appointments, and physician information allegedly involved
Other reported records
Prescription, shipment, invoice, employee, provider, clinic, Salesforce, and internal-communication data allegedly involved

Who may want to contact us

Who should keep records now?

A possible McKesson connection is worth documenting, but it is not proof that your information was involved. Direct notice or a confirmed record match will be more important as McKesson's investigation develops.

Patients or caregivers who find McKesson, CoverMyMeds, or Biologics records connected to their care

People who receive a McKesson, pharmacy, provider, employer, or business-partner incident notice

Current or former McKesson employees who receive notice or experience account misuse

People experiencing healthcare-themed phishing, identity theft, medical-identity misuse, fraud, expense, or lost time tied to the incident

What to preserve

Keep incident notices, healthcare records, and evidence of misuse

Preserve relevant records, but do not send medical records, passwords, full financial-account numbers, government identification, or unredacted credit reports through ordinary website forms.

Notices and monitoring offers

Keep the complete McKesson notice, envelope, email, enrollment instructions, deadline, and any later updates.

Relationship records

Preserve records showing your relationship with McKesson or a connected pharmacy, provider, patient-support program, employer, or business partner, including dated account, enrollment, employment, alumni, transaction, or correspondence records.

Information held about you

Save records or dated screenshots showing the contact, identity, academic, employment, financial, or profile information the organization held about you.

Suspicious communications

Keep phishing emails, texts, calls, password-reset messages, account alerts, or other communications that use organization-specific details.

Credit and account records

Preserve credit alerts, unfamiliar-account notices, fraud reports, freeze confirmations, monitoring results, and relevant financial correspondence.

Time, expenses, and harm

Track time spent securing accounts or responding to misuse, along with out-of-pocket costs, lost funds, denied credit, or other concrete effects.

Investigation focus

Issues under review

Hall Attorneys is reviewing the scope of the confirmed access and exfiltration, the accuracy of the actor's claims, McKesson's response and notice process, and harms reported by affected people.

  1. Which third-party applications were accessed and how the attackers obtained access
  2. When unauthorized access began, what data was exfiltrated, and when McKesson contained the activity
  3. How many unique patients, customers, partners, employees, providers, and other people were affected
  4. Which identity, contact, healthcare, prescription, billing, workforce, or communications fields were associated with each person
  5. Whether affected people receive complete and timely individualized notice and appropriate protection services
  6. Whether the incident leads to phishing, medical-identity misuse, prescription fraud, identity theft, financial loss, monitoring costs, or lost time

Public records reviewed

Sources for the McKesson incident

McKesson and its SEC filing confirm the incident, while BleepingComputer reports the threat actor's still-unverified claims. The page will be updated as McKesson, regulators, or other authoritative sources publish additional findings.

McKesson Corporation ·

Cybersecurity Incident Investigation Underway

McKesson's customer notice confirming unauthorized access and data exfiltration involving third-party applications and describing its ongoing response.

Read source: Cybersecurity Incident Investigation Underway

U.S. Securities and Exchange Commission ·

Form 8-K — Cybersecurity Incident

McKesson's filing identifies August 25 as the discovery date and says the investigation was in its early stages.

Read source: Form 8-K — Cybersecurity Incident

McKesson Corporation ·

CoverMyMeds — McKesson Business Overview

Describes CoverMyMeds services involving prior authorization, medication access and affordability, copay assistance, and connections among pharmaceutical companies, providers, pharmacists, payers, and patients.

Read source: CoverMyMeds — McKesson Business Overview

McKesson Corporation ·

Biologics by McKesson — Business Overview

Identifies Biologics as a McKesson specialty pharmacy supporting oncology, rare-disease, and cell and gene therapies, including prior authorization and financial-resource services.

Read source: Biologics by McKesson — Business Overview

Biologics by McKesson ·

Specialty Therapies Available Through Biologics

The current medication list states that Biologics offers more than 200 oncology, rare-disease, and cell and gene therapies and identifies example medications available through its inventory.

Read source: Specialty Therapies Available Through Biologics

Contact the firm

Found a McKesson, CoverMyMeds, or Biologics connection?

Contact Hall Attorneys with the business name you found, the general type and date of the record, whether you received notice, and any suspicious activity or loss. Do not include passwords, full account numbers, Social Security numbers, medical records, or identification documents in an initial message.

Contact Hall Attorneys

Frequently asked questions

McKesson breach FAQ

Is this a filed McKesson lawsuit?

No. This page describes an investigation by Hall Attorneys and does not state that the firm has filed a lawsuit concerning McKesson.

What has McKesson confirmed?

McKesson has confirmed a cybersecurity incident involving third-party applications and unauthorized access and exfiltration of data. Its SEC filing says the company discovered the incident on August 25, 2026.

Were 284 million McKesson patients affected?

That has not been established. ShinyHunters described approximately 284 million raw data records or lines, not unique patients, and said it did not yet know the number of unique people. McKesson has not confirmed the figure.

What information was exposed in the McKesson incident?

McKesson has not published a confirmed field list. BleepingComputer reports actor claims involving identity, contact, healthcare, prescription, billing, workforce, provider, and internal-communication data, but those claims remain unverified.

How do I know if McKesson had my information?

Search your email, text messages, patient portals, prescription bottles, shipment paperwork, and medication-support records for McKesson, CoverMyMeds, and Biologics. A match may establish a possible relationship, but it does not prove that your information was involved in this incident. McKesson has not published a final affected-person list or public lookup tool.

What records should I keep?

Keep the full incident notice and envelope or email, records showing your relationship to McKesson or a connected organization, suspicious messages, account or benefits statements, fraud reports, monitoring records, receipts, and a log of time spent responding.

Attorney Advertising

Hall Attorneys is not affiliated with McKesson Corporation or the publishers cited on this page. This page concerns an investigation, not a filed lawsuit by Hall Attorneys. Sending information does not create an attorney-client relationship. Do not send passwords, monitoring codes, complete financial-account numbers, government identification, or other highly confidential information unless specifically requested through a secure channel.