supply-chaintrade-pressNewsThe Broadside1 min read

McKesson breach hits oncology, surgical units via third-party app

The vector was a third-party application, not McKesson's core distribution systems, which is why the company didn't pull the plug on customer-facing services.


TL;DR

McKesson disclosed a cybersecurity incident Friday involving data exfiltration through an unnamed third-party application. The ShinyHunters group claimed responsibility. CTO Francisco Fraga said the company chose not to proactively disconnect systems (a move typically reserved for ransomware containment) because the breach was contained to the third-party app. On Saturday, McKesson confirmed the exfiltrated data involves customers in its oncology and surgical business units and said it has "reasonable assurance" the attackers are no longer in its systems. The company reported $106 billion in revenue last quarter and handles roughly one-third of North American prescriptions.

McKesson breach hits oncology, surgical units via third-party app
Editorial illustration · drawn by The Broadside

The incident pattern is becoming familiar in healthcare supply-chain breaches: attackers don't go through the front door. They find a third-party application with legitimate access and work from there. McKesson's disclosure follows the same shape as the Boston Scientific and Medtronic breaches reported earlier this year, each involving a different link in the healthcare supply chain.

What's notable here is what McKesson didn't do. The company didn't isolate core systems or disconnect customer-facing services, the standard play in a ransomware incident. Fraga was explicit: the company is "not proactively disconnecting systems." That restraint only makes sense if investigators are confident the intrusion stayed within the third-party application and didn't spread laterally into McKesson's distribution infrastructure. The Saturday update (confirming the attackers are out and customers can resume normal use) reinforces that read.

ShinyHunters has been on a tear in 2026. The FBI warned earlier this year that the group was exploiting Salesforce environments to steal data and demand substantial ransoms. Its May attack on a widely used educational software suite disrupted schools across the U.S., and its April breach of Medtronic exposed more than four million patient records. The group's playbook (exfiltrate first, extort second) means McKesson customers in the oncology and surgical units should expect their data to appear on the leak site if a ransom isn't paid.

For McKesson's pharmacy customers, the operational continuity is genuine good news, unlike the Change Healthcare meltdown of 2024, which paralyzed prescription processing nationwide for weeks. But the breach still exposes the growing attack surface: every third-party application connected to a $106-billion-revenue pharmaceutical distributor is a potential entry point.


Published ·Deep Fathom