[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f1vz17d6tdewfs":3},{"success":4,"breach":5},true,{"_id":6,"name":7,"title":8,"slug":9,"domain":10,"breachDate":11,"addedDate":12,"publishedAt":12,"modifiedDate":13,"contentUpdatedAt":14,"source":15,"sourceUrl":16,"sourceUrls":17,"pwnCount":22,"affectedCount":22,"affectedCountStatus":23,"affectedCountLowerBound":22,"affectedCountUnit":24,"hasEnglishDescription":4,"contentLocale":25,"availableLocales":26,"translations":28,"severity":32,"dataClasses":33,"description":57,"seoTitle":8,"seoDescription":58,"logoUrl":59,"isVerified":4,"isSensitive":4,"isSpamList":60,"isMalware":60,"company":61},"d674ebb051204c1ac41bffc6","McKesson2026","McKesson 2026 Data Breach","mckesson-2026-data-breach","mckesson.com","2026-08-20T00:00:00.000Z","2026-09-11T11:57:14.154Z","2026-09-11T14:24:08.747Z","2026-09-11T14:20:46.379Z","Official McKesson breach notice, customer update, and SEC Form 8-K","https:\u002F\u002Fwww.mckesson.com\u002Futility\u002Fcybersecurity\u002Fnotice-of-data-breach\u002F",[16,18,19,20,21],"https:\u002F\u002Fwww.mckesson.com\u002Futility\u002Fcybersecurity\u002Fcustomer-cybersecurity-information-center\u002F","https:\u002F\u002Fwww.sec.gov\u002FArchives\u002Fedgar\u002Fdata\u002F927653\u002F000092765326000247\u002Fmck-20260825.htm","https:\u002F\u002Fwww.securityweek.com\u002Fmckesson-confirms-data-breach-as-attacker-deadline-looms\u002F","https:\u002F\u002Ftechcrunch.com\u002F2026\u002F08\u002F31\u002Fhackers-claim-millions-of-patient-records-stolen-during-data-breach-at-healthcare-giant-mckesson\u002F",null,"unknown","people","en",[25,27],"tr",{"en":29,"tr":30},{"slug":9},{"slug":31},"mckesson-2026-veri-ihlali","Unknown",[34,35,36,37,38,39,40,41,42,43,44,45,46,47,48,49,50,51,52,53,54,55,56],"Names","Physical addresses","Phone numbers","Email addresses","Patient IDs","Dates of birth","Health insurance information","Health plan member identification numbers","Medical record numbers","Dates of medical service","Healthcare provider information","Diagnoses","Medication information","Test results","Medical images","Treatment information","Billing information","Claims information","Account numbers","Credit or debit card numbers","Financial information","Social Security numbers","Guarantor information","\u003Cp>\u003Cstrong>McKesson discovered the cybersecurity incident on August 25, 2026\u003C\u002Fstrong>, after employee corporate accounts were targeted. Its investigation placed the activity between August 20 and 25 and confirmed unauthorized access to third-party applications and the exfiltration of data from them. In an August 28 SEC filing, McKesson said the investigation was at an early stage and it had not determined the incident to be material or reasonably likely to materially affect the company.\u003C\u002Fp>\u003Cp>McKesson’s August 29 customer update linked the access to \u003Cstrong>a subset of customers in its Oncology &amp; Multispecialty and Medical-Surgical business units\u003C\u002Fstrong>. Ordering, distribution centers, product shipments, systems and services remained operational. The company also said it had reasonable assurance that no unauthorized activity remained in its systems.\u003C\u002Fp>\u003Cp>A September 8 substitute notice explained that McKesson may hold personal and protected health information through the healthcare providers it supplies, so someone may be involved without having a direct McKesson account. Potential fields vary by person and may include identity and contact details, patient identifiers, birth dates, insurance information, medical records and care details, billing and claims information, account, card or banking data, and Social Security numbers. Records may concern patients, guarantors or others. \u003Cstrong>No affected-person or unique-record total was disclosed.\u003C\u002Fstrong>\u003C\u002Fp>\u003Cp>McKesson said it activated incident-response procedures, engaged external cybersecurity experts, notified law enforcement, contained the incident and added safeguards. Its data review remains ongoing, after which it plans to coordinate individual notifications with healthcare-provider customers. The substitute notice offers two years of complimentary credit monitoring and identity-theft protection to people who believe they may have been affected.\u003C\u002Fp>","McKesson disclosed an August 20-25, 2026 incident involving third-party applications and unauthorized data exfiltration.","\u002Fuploads\u002Flogo\u002Fmckesson-2026-veri-ihlali-d674ebb05120.webp",false,{"name":62,"sector":63,"country":64,"website":10,"websiteArchiveUrl":65,"websiteStatus":65,"websiteCheckedAt":22},"McKesson Corporation","Healthcare","United States",""]